About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline

LCD-76-102 1 (1978-04-28)

handle is hein.gao/gaobaaxao0001 and id is 1 raw text is: 




DOCUMENT RESUME


05-40 - [ B12416201 ]

c.hallenqes of Protecting Personal Information in an Expandiny
lederal Computer Network Environment. LCD-76-102; B-146864.
A)ril 28, 1978. 42 pp. + 2 appendices (6 pp.).

Report to the Congress; by Elmer B. Staats, Comptrcller General.

Issue Area: Federal Information: Protection of Information in
    ADP Systems (1403); Automatic Data Processing (100).
Contact: Logistics and Communications Eiv.
Budget Function: General Government: General Ptoperty and
    Records anagetent (804).
Orqaniz&tioa Concerned: Office of anagement aad Budget.
Congressional Relevance. House Coaxittoe on Post office and
    Civil service; Senate Committee on the Judiciarl; Ccngress.
Authority: Brooks Act (P.L. 89-306). Privacy Act of 1974.

         The concept of a Fedexal computer Letwork and the
attendant benefits of economy and efficiency was reccglir-zed when
the Brocks Act was enact'.d in 1965. Since the enactment of this
leqislati u. ptxblic and pri, e concern has grown over the
ability oi  .osputer systems and networks to provide adequate
protcti-.on for personal information maintained about U.S.
citi-p.s. FindinqsConclusions: The concept of a
Governm'nt-wide computec nstwork psosents a dilemma: should the
Government take advantage of the eccroiies that may be possible
trom using multiuseL teleprocessing iystems rather than
individual agency owned and operated data processing systers or
protect thb individual's right to privacy ty prohititing such
networks? This dilemma could be solved and eccromier realized if
adequate controls could be 34(ined and esteblished to ensure
confidentiality of data. The msjor threat to privacy invasion
stems from misuse of personel information ty individuals having
authorized access, and i secondary threat stems from individuals
not allowed access to the information who have the technical
ability to circumvent security measures. The risk to personal
information varies with +he type of data involved, the
effectiveness of the controls  xercised, and the configuration
of the computer network. Hhile absolute security cannot be
assureA, a hiqh level of protection can te provided in a
multinjer computer network. Recommendations: The Director,
Office of Management and Budget, should take action to provide
Federal agencies with comprehensive guidelines that: concain the
definitions and criteria necessary tc Fermit an assessment of
their security requirements; provide the methodology to te used
in conducting the assessment; identify the physical,
administrative, and technical safeguards that should be applied
in satisfying their security requirements; and specify the mears
to justify the associated cost. (RRS)

What Is HeinOnline?

HeinOnline is a subscription-based resource containing thousands of academic and legal journals from inception; complete coverage of government documents such as U.S. Statutes at Large, U.S. Code, Federal Register, Code of Federal Regulations, U.S. Reports, and much more. Documents are image-based, fully searchable PDFs with the authority of print combined with the accessibility of a user-friendly and powerful database. For more information, request a quote or trial for your organization below.



Contact us for annual subscription options:

Already a HeinOnline Subscriber?

profiles profiles most