<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1803a3ee8">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <namePart>Accounting and Information Management Division</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2000-02-17</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>17 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:T-AIMD-00-97</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-97</identifier>
<identifier type="local">P0b002ee1803a3ee8</identifier>
<identifier type="former package identifier">f:ai00097t</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-24</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-T-AIMD-00-97</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-T-AIMD-00-97</accessId>
 <reportNumber>T-AIMD-00-97</reportNumber>
 <subject>Internal controls</subject>
 <subject>Confidential communication</subject>
 <subject>Data integrity</subject>
 <subject>Information resources management</subject>
 <subject>Information leaking</subject>
 <subject>Computer security</subject>
 <subject>Hackers</subject>
 <subject>Computer crimes</subject>
 <subject>Financial management systems</subject>
 <subject>Computer networks</subject>
 <identifier>National Plan for Information Systems Protection</identifier>
 <type>Testimony</type>
 <seriesAbbrev>AIMD</seriesAbbrev>
</extension>
<titleInfo>
 <title>Information Security: Fundamental Weaknesses Place EPA</title>
</titleInfo>
<abstract>Pursuant to a congressional request, GAO discussed its recent review of
information security at the Environmental Protection Agency (EPA).&lt;p/&gt;GAO noted that: (1) GAO&apos;s review found serious and pervasive problems
that essentially render EPA&apos;s agencywide information security program
ineffective; (2) current security program planning and management is
largely a paper exercise that has done little to substantively identify,
evaluate, and mitigate risks to the agency&apos;s data systems; (3) GAO&apos;s
tests of computer-based controls have concluded that the computer
operating systems and the agencywide computer network that support most
of EPA&apos;s mission-related and financial operations are riddled with
security weaknesses; (4) many of the most serious weaknesses--those
related to inadequate protection from intrusions via the Internet and
poor security planning--had been previously reported to EPA management
in 1997 by EPA&apos;s Inspector General; (5) the negative effects of such
weaknesses are illustrated by EPA&apos;s own records which show several
serious computer security incidents in the last 2 years that have
resulted in damage and disruption to agency operations; (6) GAO
identified deficiencies in EPA&apos; incident detection and handling
capabilities that draw into question EPA&apos;s ability to fully understand
or assess the nature of or damage due to its computer security breaches;
(7) accordingly, EPA&apos;s computer systems and the operations that rely on
these systems are highly vulnerable to tampering, disruption, and
misuse; (8) moreover, EPA cannot ensure the protection of sensitive
business and financial data maintained on its larger computer systems or
supported by its agencywide network; and (9) GAO&apos;s work has sensitized
EPA to the seriousness of these issues and agency officials have
informed GAO of some corrective actions and announced other plans which,
if properly implemented, can begin to address several of these serious
problems.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-97/html/GAOREPORTS-T-AIMD-00-97.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-97/pdf/GAOREPORTS-T-AIMD-00-97.pdf</url>
</location>
<identifier type="preferred citation">GAO/T-AIMD-00-97</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-97</url>
</location>
<note>Testimony</note>
<extension>
 <searchTitle>GAO/T-AIMD-00-97; Information Security: Fundamental Weaknesses Place EPA;
            </searchTitle>
</extension>
<subject>
 <topic>Internal controls</topic>
 <topic>Confidential communication</topic>
 <topic>Data integrity</topic>
 <topic>Information resources management</topic>
 <topic>Information leaking</topic>
 <topic>Computer security</topic>
 <topic>Hackers</topic>
 <topic>Computer crimes</topic>
 <topic>Financial management systems</topic>
 <topic>Computer networks</topic>
 <topic>National Plan for Information Systems Protection</topic>
</subject>
</mods>