About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline

GAO-09-633R 1 (2009-04-28)

handle is hein.gao/gaobaanna0001 and id is 1 raw text is: 

   i
   ~G A 0

     SAcoutabillty ' ntcqrity Reiity
United States Government Accountability Office
Washington, DC 20548
                                             On April 29, 2009, GAO revised this product to
                                             clarify the scope and focus of BPD's
         April 28, 2009                      compensating controls with respect to
                                             detecting potential misstatements in the
          The Honorable Van Zeck             Schedule of Federal Debt.
          Commissioner
          Bureau of the Public Debt

          Subject: Bureau of the Public Debt: Areas for Improvement in Information Security
                 Controls

          Dear Mr. Zeck:

          In connection with fulfilling our requirement to audit the financial statements of the
          U.S. government,' we audited and reported on the Schedules of Federal Debt
          Managed by the Bureau of the Public Debt (BPD) for the fiscal years ended
          September 30, 2008 and 2007.2 As part of these audits, we performed a review of the
          general and application information security controls over key BPD financial
          systems.

          As we reported in connection with our audit of the Schedules of Federal Debt for the
          fiscal years ended September 30, 2008 and 2007, we concluded that BPD maintained,
          in all material respects, effective internal control relevant to the Schedule of Federal
          Debt related to financial reporting and compliance with applicable laws and
          regulations as of September 30, 2008, that provided reasonable assurance that
          misstatements, losses, or noncompliance material in relation to the Schedule of
          Federal Debt would be prevented or detected on a timely basis. However, we found
          deficiencies involving information security controls that we do not consider to be
          significant deficiencies. With regard to financial reporting and compliance with
          applicable laws and regulations, BPD mitigated the potential effect of such control
          deficiencies with physical security measures, a program of monitoring user and
          system activity, and compensating management and reconciliation controls.
          Nevertheless, these matters warrant BPD management's attention and action.




          '31 U.S.C. § 331(e).
          2GAO, Financial Audit: Bureau of the Public Debt's Fiscal Years 2008 and 2007 Schedules of Federal
          Debt, GAO-09-44 (Washington, D.C.: Nov. 7, 2008).
          3A significant deficiency is a control deficiency, or combination of control deficiencies, that adversely
          affects the entity's ability to initiate, authorize, record, process, or report financial data reliably in
          accordance with U.S. generally accepted accounting principles such that there is more than a remote
          likelihood that a misstatement of the entity's financial statements that is more than inconsequential
          will not be prevented or detected. A control deficiency exists when the design or operation of a control
          does not allow management or employees in the normal course of performing their assigned functions
          to prevent or detect misstatements on a timely basis.


GAO-09-633R Information Security Controls at BPD


Page 1

What Is HeinOnline?

HeinOnline is a subscription-based resource containing thousands of academic and legal journals from inception; complete coverage of government documents such as U.S. Statutes at Large, U.S. Code, Federal Register, Code of Federal Regulations, U.S. Reports, and much more. Documents are image-based, fully searchable PDFs with the authority of print combined with the accessibility of a user-friendly and powerful database. For more information, request a quote or trial for your organization below.



Contact us for annual subscription options:

Already a HeinOnline Subscriber?

profiles profiles most