About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline

AIMD-93-7R 1 (1993-07-19)

handle is hein.gao/gaobackjs0001 and id is 1 raw text is: 141181i


GAO


B-233809


July 19, 1993


The Honorable Gary A. Condit
Chairman, Information, Justice,
  Transportation and Agriculture
  Subcommittee
Committee on Government Operations
House of Representatives

Dear Mr. Chairman:


O~LU)
     C/-



Z  Q  C.

Z     -~

    0:



 R ;4


149787


This letter responds to the October 30, 1992, request of
the former Chairman that we review Federal Information
Resources Management Regulation (FIRMR) Bulletin C-22,
which provides guidance to federal agencies on the
security and privacy protection of federal computer
resources. Specifically, we were asked to determine
whether (1) the bulletin's procedures on the disposition
of sensitive automated information are adequate to
prevent such incidents as the one in which a U.S.
Attorney's Office in Lexington, Kentucky, sold surplus
computer equipment later found to contain highly
sensitive information; and (2) the General Services
Administration (GSA) sought input from staff who worked
on the investigation of the Kentucky matter while
developing the bulletin. In a discussion with your
office, staff expressed your interest in obtaining the
results of our review.

To address our objectives, we reviewed Bulletin C-22 and
interviewed GSA officials responsible for issuing this
guidance. We also interviewed officials from the
National Institute of Standards and Technology (NIST) who
developed the sections of the bulletin on the disposition
of sensitive information, and reviewed other NIST
guidance and information on this subject. We also
reviewed National Security Agency (NSA) guidance on the
disposition of sensitive and classified automated
information.


GAO/AIMD-93-7R, GSA's Computer Security Guidance


United States
General Accounting Offie
Washington, D.C. 20540

Accounting and Informattion
Management Division


A

What Is HeinOnline?

HeinOnline is a subscription-based resource containing thousands of academic and legal journals from inception; complete coverage of government documents such as U.S. Statutes at Large, U.S. Code, Federal Register, Code of Federal Regulations, U.S. Reports, and much more. Documents are image-based, fully searchable PDFs with the authority of print combined with the accessibility of a user-friendly and powerful database. For more information, request a quote or trial for your organization below.



Contact us for annual subscription options:

Already a HeinOnline Subscriber?

profiles profiles most