Information Security:
Software Change Controls at the Department of Justice
AIMD-00-191R: Published: Jun 30, 2000. Publicly Released: Jun 30, 2000.
Additional Materials:
- Full Report:
Contact:
(202) 512-6253
contact@gao.gov
Office of Public Affairs
(202) 512-4800
youngc1@gao.gov
Pursuant to a congressional request, GAO reviewed software change controls at the Department of Justice (DOJ), focusing on: (1) whether key controls as described in agency policies and procedures regarding software change authorization, testing, and approval complied with federal guidance; and (2) the extent to which agencies contracted for year 2000 remediation of mission-critical systems and involved foreign nationals in these efforts.
GAO noted that: (1) based on GAO's interviews and review of documented security policies and procedures, background screenings of personnel involved in the software change process were a routine security control at DOJ; (2) officials told GAO that all 37 contracts for remediation services of 137 mission-critical systems included provisions for background checks of contractor staff; (3) this is important because GAO found that although foreign nationals were involved in one Drug Enforcement Administration (DEA) contract, officials told GAO that adequate personnel security controls were practiced; (4) however, GAO identified several weaknesses related to formal policies and procedures for software change control and contract oversight; (5) formally documented component-level policies and procedures at DEA, the Immigration and Naturalization Service (INS), and the Antitrust Division (ATR) did not meet federal criteria; (6) specifically, the documented procedures at these components did not address the following key software change controls: (a) ATR procedures did not address testing of changes, protection of application software libraries, and restricting and monitoring of access to operating system software; (b) DEA procedures did not adequately address restricting access to program code in and monitoring access to operating system software; and (c) INS procedures did not adequately address control of application software libraries; (7) based on GAO's interviews, DEA and the Federal Bureau of Investigation (FBI) officials were not familiar with contractor practices for software management when source code was out of the agency's direct control; and (8) specifically, FBI and DEA electronically transmitted code for six mission-critical systems to contractor facilities for remediation, and agency officials could not readily determine how the code was protected during and after transit to the contractor facilities.
Oct 15, 2020
-
Data Security:
Recent K-12 Data Breaches Show That Students Are Vulnerable to HarmGAO-20-644: Published: Sep 15, 2020. Publicly Released: Oct 15, 2020.
Oct 9, 2020
-
Aviation Cybersecurity:
FAA Should Fully Implement Key Practices to Strengthen Its Oversight of Avionics RisksGAO-21-86: Published: Oct 9, 2020. Publicly Released: Oct 9, 2020.
Sep 22, 2020
-
Cybersecurity:
Clarity of Leadership Urgently Needed to Fully Implement the National StrategyGAO-20-629: Published: Sep 22, 2020. Publicly Released: Sep 22, 2020.
Sep 21, 2020
-
Information Security and Privacy:
HUD Needs a Major Effort to Protect Data Shared with External EntitiesGAO-20-431: Published: Sep 21, 2020. Publicly Released: Sep 21, 2020.
Sep 17, 2020
-
Critical Infrastructure Protection:
Treasury Needs to Improve Tracking of Financial Sector Cybersecurity Risk Mitigation EffortsGAO-20-631: Published: Sep 17, 2020. Publicly Released: Sep 17, 2020.
Sep 16, 2020
-
Veterans Affairs:
VA Needs to Address Persistent IT Modernization and Cybersecurity ChallengesGAO-20-719T: Published: Sep 16, 2020. Publicly Released: Sep 16, 2020.
Aug 18, 2020
-
Cybersecurity:
DHS and Selected Agencies Need to Address Shortcomings in Implementation of Network Monitoring ProgramGAO-20-598: Published: Aug 18, 2020. Publicly Released: Aug 18, 2020.
May 27, 2020
-
Cybersecurity:
Selected Federal Agencies Need to Coordinate on Requirements and Assessments of StatesGAO-20-123: Published: May 27, 2020. Publicly Released: May 27, 2020.
May 13, 2020
-
Management Report:
Improvements Are Needed to Enhance the Internal Revenue Service's Information System Security ControlsGAO-20-411R: Published: May 13, 2020. Publicly Released: May 13, 2020.
Apr 24, 2020
-
Information Security:
FCC Made Significant Progress, but Needs to Address Remaining Control Deficiencies and Improve Its ProgramGAO-20-265: Published: Mar 25, 2020. Publicly Released: Apr 24, 2020.
Looking for more? Browse all our products here

Explore our Key Issues on Information Security