About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline

HRD-79-114 1 (1979-09-04)

handle is hein.gao/gaobaazqn0001 and id is 1 raw text is: 



      M iUNITED STATES GENERAL ACCOUNTING OFFICE       c4l       (  .

        .1WASHINGTON, D C 20548


HUMAN RESOURCES
   PIVISION
     B-164031(4)
                                              SEP 4 1979


     The Honorable Abraham Ribicoff
     Chairman, Committee on -    0JIII
     Governmental Affairs
     United States Senate
                                                       110322
     Dear Mr. Chairman:

          Subject- Followup on Computer Security at the
                    Social Security Administratio    We4
                    (HRD-79-114)                -   

          Your March 9, 1978, letter relating to our report
     to the Social Security Administration on computer security
     at its headquarters (HRD-78-73, Feb. 21, 1978) Fequeste
     that we report to you on Social Security's improvements
     after an appropriate length of time. On April 25, 1978,
     the Social Security Administration informed us of actions
     taken to correct the problems we identified. (See enc. I.)
     Since that time, we have verified that Social Security has
     acted on each of our recommendations.

          On June 5, 1978, we issue a report to Congressmen
      John E. Moss and Charles Rose (HRD-78-116) which we are
      including for your information as enclosure II. The Con-
      gressmen requested an evaluation of the security procedures
      Social Security used to protect beneficiary records. They
      were interested in both automated records and hard copy
      folders located in field offices, private insurance companies,
      and State disability determination offices.

          We reported on several management problems leading to
      possible misuse, abuse, or destruction of Social Security
      beneficiary records. The June 5 report discussed the limited
      safeguards provided by Social Security to protect both auto-
      mated beneficiary records and documents supporting beneficiary
      claims. Some of the more significant issues were (1) unlimited
      and unrestricted access to terminals, (2) ability to create as
      well as query beneficiary files from most terminals, (3) failure
      to use audit trail features within the system, (4) failure to
      always lock terminals during nonworking hours, (5) safeguarding


                                                   (990515)

What Is HeinOnline?

HeinOnline is a subscription-based resource containing thousands of academic and legal journals from inception; complete coverage of government documents such as U.S. Statutes at Large, U.S. Code, Federal Register, Code of Federal Regulations, U.S. Reports, and much more. Documents are image-based, fully searchable PDFs with the authority of print combined with the accessibility of a user-friendly and powerful database. For more information, request a quote or trial for your organization below.



Contact us for annual subscription options:

Already a HeinOnline Subscriber?

profiles profiles most