About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline

LCD-79-109 1 (1979-03-21)

handle is hein.gao/gaobaazyf0001 and id is 1 raw text is: 




LMl 10907


GI. (I


     Unitd !dt~sC~~ierI AcouningOffli.c
We~shinptcon. D'- 20548


L-163074


*1j .


Loiistics~ and
Communhications
Division


LIAR 2i 1173.


4he Honorable Harold Brown
The Secretary of Defense


     We have completed our examinat o  ftutomated systems
security programsgin the Department of Defense (DOD) and
other major Federal agencies. Our efforts resulted in
a report, Automated. Systems Security--Pedera. Agencies
Should Strengthen Safeguards Over Personal and Other Sensi-
tive Data (LCD-78-123, Jan. 23, 1979).   (See enc.)

     The January report concludes that agocy management
attention to prodrams for protecting data in automated
systems was deficient. However, we see potential for im-
provement if agencies respond aggressively to the Office of
Management and Budget (0MB) Circular !-71, TM 1 (Security
of Federal Automated Infomnation Systems, July 27, 1978).
TPhe report states that thebe requirements are now being
coupled with broader concerns for improving agency con-
trols over fraud and abuse. As you know, the President's
December 13, 1978, memorandum to heads of executive depart-
ments and agencies requires their personal attention in
these areas.


       lniti)Illy, our review was to include automated systems
  secur.ity programs in selected civil agencies, DOD, and com-
  ponent services. We advised DOD that we would not be di-
  rectly examining its activities because of its extensive
-.internal audits. Instead, these audits and the implications
  for security programs of audit findings were assessed.

       We identified and analyzed 106 computer security-
  oriented Duits related to over 270 fvcilities and/or systems.
  These adits were conducted by the Defense Audit Service,.
  the Army Audit Agency, the Naval Audit Service, and the Air
  Force Audit Agency. We also reviewed with. 'DOD and compcnent
  serv ice policy officials the extent of programs and guide-
  lines to protect sensitive data.


ic~7


LCD-79-109
(911121)
(941145)


I

What Is HeinOnline?

HeinOnline is a subscription-based resource containing thousands of academic and legal journals from inception; complete coverage of government documents such as U.S. Statutes at Large, U.S. Code, Federal Register, Code of Federal Regulations, U.S. Reports, and much more. Documents are image-based, fully searchable PDFs with the authority of print combined with the accessibility of a user-friendly and powerful database. For more information, request a quote or trial for your organization below.



Contact us for annual subscription options:

Already a HeinOnline Subscriber?

profiles profiles most