<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee180376f4d">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <namePart>Accounting and Information Management Division</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">1999-09-30</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>15 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:T-AIMD-99-302</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-99-302</identifier>
<identifier type="local">P0b002ee180376f4d</identifier>
<identifier type="former package identifier">f:ai99302t</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-28</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-T-AIMD-99-302</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-T-AIMD-99-302</accessId>
 <reportNumber>T-AIMD-99-302</reportNumber>
 <subject>Computer security</subject>
 <subject>Data integrity</subject>
 <subject>Internal controls</subject>
 <subject>Proposed legislation</subject>
 <subject>Computer crimes</subject>
 <subject>Information resources management</subject>
 <subject>Data encryption</subject>
 <subject>Confidential communication</subject>
 <subject>Information systems</subject>
 <type>Testimony</type>
 <seriesAbbrev>AIMD</seriesAbbrev>
</extension>
<titleInfo>
 <title>Information Security: The Proposed Computer Security</title>
</titleInfo>
<abstract>Pursuant to a congressional request, GAO discussed the proposed Computer
Security Enhancement Act of 1999 (H.R. 2413), focusing on: (1) the
urgent need to strengthen computer security across the federal
government; (2) the current and future privacy concerns with any
computer security legislation; (3) GAO&apos;s views on the proposed act; and
(4) what can be done to further strengthen security program management
at individual agencies as well as governmentwide leadership,
coordination, and oversight.&lt;p/&gt;GAO noted that: (1) the dramatic increase of computer interconnectivity
and the popularity of the Internet, while facilitating access to
information, are factors that also make it easier for individuals and
groups with malicious intentions to intrude into inadequately protected
systems and use such access to obtain sensitive information, commit
fraud, or disrupt operations; (2) attacks on and misuse of federal
computer and telecommunications resources are of increasing concern
because these resources are virtually indispensable for carrying out
critical operations and protecting sensitive data and assets; (3) the
need to protect sensitive data and systems must be weighed not only
against cost and feasibility concerns but also the privacy and security
interests of individual citizens, private businesses, as well as
national security and law enforcement agencies; (4) while information
vulnerabilities cannot be eliminated through the use of any single tool,
cryptography can help businesses ensure the confidentiality and
integrity of information in transit and storage and verify the asserted
identity of individuals and computer systems; (5) the proposed act
particularly focuses on the role the National Institute of Standards and
Technology (NIST) plays in assisting federal agencies to protect their
systems and promote technology solutions to security protection based on
private sector offerings; (6) it is important to recognize that there is
no legislative substitute that could be put in place to provide the
increased management attention and due diligence necessary to implement
and ensure the effectiveness of information security controls; (7) it is
also important to ensure that NIST retain the ability to develop
security standards for unclassified data and decide which industry
standards are appropriate for federal agencies, and that agencies
themselves consistently implement such standards; and (8) Congress needs
to consider stronger measures that would ensure that executive agencies
are: (a) carrying out their responsibilities outlined in laws and
regulations requiring them to protect their information resources; (b)
identifying and ranking the most significant information security issues
facing federal agencies; (c) promoting information security risk
awareness among senior agency officials whose critical operations rely
on automated systems; (d) strengthening information technology workforce
skills; (e) evaluating the security of systems on a regular basis; and
(f) providing for periodically evaluating agency performance from a
governmentwide perspective and acting to address shortfalls.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-99-302/html/GAOREPORTS-T-AIMD-99-302.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-99-302/pdf/GAOREPORTS-T-AIMD-99-302.pdf</url>
</location>
<identifier type="preferred citation">GAO/T-AIMD-99-302</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-99-302</url>
</location>
<note>Testimony</note>
<extension>
 <searchTitle>GAO/T-AIMD-99-302; Information Security: The Proposed Computer Security;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Data integrity</topic>
 <topic>Internal controls</topic>
 <topic>Proposed legislation</topic>
 <topic>Computer crimes</topic>
 <topic>Information resources management</topic>
 <topic>Data encryption</topic>
 <topic>Confidential communication</topic>
 <topic>Information systems</topic>
</subject>
</mods>