<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee18038afc7">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <namePart>Accounting and Information Management Division</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2000-02-01</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>14 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:T-AIMD-00-72</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-72</identifier>
<identifier type="local">P0b002ee18038afc7</identifier>
<identifier type="former package identifier">f:ai00072t</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-23</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-T-AIMD-00-72</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-T-AIMD-00-72</accessId>
 <reportNumber>T-AIMD-00-72</reportNumber>
 <subject>Internal controls</subject>
 <subject>Computer networks</subject>
 <subject>Data integrity</subject>
 <subject>Information resources management</subject>
 <subject>Information systems</subject>
 <subject>Computer security</subject>
 <subject>Strategic information systems planning</subject>
 <subject>Joint ventures</subject>
 <identifier>National Plan for Information Systems Protection</identifier>
 <type>Other Written Product</type>
 <seriesAbbrev>AIMD</seriesAbbrev>
</extension>
<titleInfo>
 <title>Critical Infrastructure Protection: Comments on the</title>
</titleInfo>
<abstract>Pursuant to a congressional request, GAO discussed the National Plan for
Information Systems Protection, focusing on: (1) a detailed overview of
the plan; (2) opportunities for sharpening the plan&apos;s proposals for
improving the federal government&apos;s security programs; and (3) the
challenges facing the government in building the public-private
partnerships necessary for comprehensive infrastructure protections.&lt;p/&gt;GAO noted that: (1) the National Plan for Information Systems Protection
is intended as a first major element of a more comprehensive effort to
protect the nation&apos;s information systems and critical assets from future
attacks; (2) this preliminary version focuses largely on federal efforts
being undertaken to protect the nation&apos;s critical cyber-based
infrastructures; (3) subsequent versions are to address a broader range
of concerns, including the specific role industry and state and local
governments will play in protecting physical and cyber-based
infrastructures from deliberate attack as well as international aspects
of critical infrastructure protection; (4) the end goal of this process
is to develop a comprehensive national strategy for infrastructure
assurance as envisioned by Presidential Decision Directive 63; (5)
making the federal government a model of good information security is
essential to the plan&apos;s success; (6) recent audits conducted by GAO and
agency inspectors general show that 22 of the largest federal agencies
have significant computer security weaknesses, ranging from poor
controls over access to sensitive systems and data, to poor control over
software development and changes, and nonexistent or weak continuity of
service plans; (7) agencies have not established security management
programs to ensure that controls, once implemented properly, are
effective on an ongoing basis; (8) GAO also observed that other
crosscutting actions--ranging from clarifying the roles and
responsibilities of the many entities involved in information security
to strengthening oversight, to securing adequate technical expertise and
funding--were needed in seven key areas to provide greater assurance
that critical infrastructure objectives can be met; (9) the second facet
of the plan focuses on developing a public-private partnership to
protect the nation&apos;s infrastructure; and (10) in doing so, the plan
proposes developing mechanisms and improving incentives for the private
sector to cooperate voluntarily with the federal government, as well as
with state and local governments, to work together to provide for the
common defense of the infrastructure.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-72/html/GAOREPORTS-T-AIMD-00-72.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-72/pdf/GAOREPORTS-T-AIMD-00-72.pdf</url>
</location>
<identifier type="preferred citation">GAO/T-AIMD-00-72</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-72</url>
</location>
<note>Other Written Product</note>
<extension>
 <searchTitle>GAO/T-AIMD-00-72; Critical Infrastructure Protection: Comments on the;
            </searchTitle>
</extension>
<subject>
 <topic>Internal controls</topic>
 <topic>Computer networks</topic>
 <topic>Data integrity</topic>
 <topic>Information resources management</topic>
 <topic>Information systems</topic>
 <topic>Computer security</topic>
 <topic>Strategic information systems planning</topic>
 <topic>Joint ventures</topic>
 <topic>National Plan for Information Systems Protection</topic>
</subject>
</mods>