Computer Security:

Weaknesses Continue to Place Critical Federal Operations and Assets at Risk

GAO-01-600T: Published: Apr 5, 2001. Publicly Released: Apr 5, 2001.

Additional Materials:


Joel C. Willemssen
(202) 512-6253


Office of Public Affairs
(202) 512-4800

This testimony discusses GAO's analysis of security audits at federal agencies. The widespread interconnectivity of computers poses significant risks to federal computer systems and the operations and the infrastructures they support. GAO's evaluations show that federal computer systems are riddled with weaknesses that continue to put critical operations and assets at risk. GAO found weaknesses in following six areas: (1) security program management, (2) access controls, (3) software development and change controls, (4) segregation of duties, (5) operating systems controls, and (6) service continuity. Weaknesses in these areas place a broad range of critical operations and assets at risk for fraud, misuse, and disruption. Federal agencies have tried to address these problems, and many have good remedial efforts underway. However, these efforts will not be fully effective and lasting unless they are supported by a strong agencywide security management framework. Establishing such a management framework requires that agencies take a comprehensive approach that involves both (1) senior agency program managers who understand which aspects of their missions are the most critical and sensitive and (2) technical experts who know the agencies' systems and can suggest appropriate technical security control techniques.

Dec 20, 2018

Dec 18, 2018

Dec 6, 2018

Nov 13, 2018

Sep 17, 2018

Sep 7, 2018

Sep 6, 2018

Jul 31, 2018

Jul 25, 2018

Jul 12, 2018

Looking for more? Browse all our products here