Information Systems:

Agencies Overlook Security Controls During Development

IMTEC-88-11S: Published: May 31, 1988. Publicly Released: May 31, 1988.

Additional Materials:


Office of Public Affairs
(202) 512-4800

GAO provided a supplement to its report on agencies' development of automated systems. GAO provided information regarding the model it used in determining that federal agencies it reviewed did not meet federal criteria or practice sound system development methods for successfully incorporating appropriate security controls during their development of automated information systems.

GAO discussed the model's: (1) construction, which it based on federal guidance and standards and generally accepted practices of software engineering; and (2) sub-activities, including the initiation, definition, design, construction, integration, installation, and test phases. GAO also discussed the potential effects of agencies not performing security activities during each of the model's systems development phases.

Sep 20, 2016

Sep 15, 2016

Jun 29, 2016

Jun 21, 2016

Apr 28, 2016

Apr 14, 2016

Apr 12, 2016

Mar 23, 2016

Dec 17, 2015

Nov 17, 2015

Looking for more? Browse all our products here