About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline

B-211147 1 (1983-03-18)

handle is hein.gao/gaobabnet0001 and id is 1 raw text is: 


N UTED STATES GEJ.,AL ACCOUNTING OFCE                      ?4E
                           REGIONAL OFFICE
                         Room 1992, Federal Building
                         Sattle, Washinitort D,3174

                                                     MAR 1 8 1083


Mr. Peter T. Johnson, Administrator

onneville Power Administration
Department of Energy                                    122958
P. 0. Box 3621
Portland, Oregon 97208

Dear Mr. Johnson:

      Subject.: Bonneville Power Administration Contcol
                System's Computer Security--More Needs To
                Be Done (B-211147).

      As part of our recent review of automatic data processing
 (ADP) management at Bonneville Power Administration (3onneviJle),
 we madae a limited review of computer security at the control
 syst*ern's Dittmer computer center in Vancouver, Washington.
 Althogh Bonneville has made some strides towards developing and
 impleowentin_j a computer security program, as required in 21.iice
 of fa.Pg._,e.t and Budget (OMB) Circular A-71, Trausmita].
 M' mor:induin Number 1 1/ and Department o. Ene::qj (DOE) Order
 1360.2, 2/ it needs to do more.

      Recently Bonnevill.e's Division of System Operations ap-
pointed a computer protection program inaaqer (CPPM), irdentified
critical and sensitive data processing systems, and assessed
risks and threats to the Dittmer computL.r enter' on-goiring
op ations. However, during our review we found thatL,

      --Written compnuter security procedures for the Dittmer
        con'.it;Y enter havre not been developed or iapiemnted.
        -T   .,ri ., said that h- was drafting procedures, burt woild
        not finalize them until he ensured their compatib !i':.y
        with Bonnevill-'s qener. purpose computer security


 I/Office of M4anageineat and Budget Circular A--71 Transrmittal
   Memorandum Number 1, Security of Federal Automated Infforriatioi
   Systeins, July 27, 1978.

 2/DepaiLtment of Energy Ocder 1360.2, Computer Security Program
   For Unclassified Computer svems, March 9, 1979.

What Is HeinOnline?

HeinOnline is a subscription-based resource containing thousands of academic and legal journals from inception; complete coverage of government documents such as U.S. Statutes at Large, U.S. Code, Federal Register, Code of Federal Regulations, U.S. Reports, and much more. Documents are image-based, fully searchable PDFs with the authority of print combined with the accessibility of a user-friendly and powerful database. For more information, request a quote or trial for your organization below.



Contact us for annual subscription options:

Already a HeinOnline Subscriber?

profiles profiles most