Menu Search Account

LegiStorm

Get LegiStorm App Visit Product Demo Website
» Get LegiStorm App
» Get LegiStorm Pro Free Demo

Information Security: Comments on Proposed Government Information Act of 1999

  Premium   Download PDF Now (13 pages)
Report Type Reports and Testimonies
Report Date March 2, 2000
Report No. T-AIMD-00-107
Subject
Summary:

The proposed Government Information Security Act of 1999--S. 1993--seeks to strengthen information security practices throughout the federal government. GAO's work has shown that almost all government agencies are plagued by poor computer security. The dramatic rise in computer interconnectivity has increased the risk of severe disruptions to government operations. Government officials are increasingly worried about attacks from individuals and groups with malicious intentions, such as terrorists and nations engaging in information warfare. S.1993 would update the legal framework that supports federal information security requirements and would address widespread federal information security weaknesses. In particular, the bill would prescribe a risk-based approach to information security and independent audits of security controls. It also would approach security from a governmentwide perspective, taking steps to accommodate the varying information needs of both national security and civilian agency operations. This testimony discusses how this proposal could substantially improve the federal government's efforts to address its computer security problems. GAO also raises two additional issues--the need for better-defined control standards and centralized leadership--that, if addressed, could further strengthen security practices and oversight.

« Return to search Government Accountability Office reports