Computer Security:

Weaknesses Continue to Place Critical Federal Operations and Assets at Risk

GAO-01-600T: Published: Apr 5, 2001. Publicly Released: Apr 5, 2001.

Additional Materials:


Joel C. Willemssen
(202) 512-6253


Office of Public Affairs
(202) 512-4800

This testimony discusses GAO's analysis of security audits at federal agencies. The widespread interconnectivity of computers poses significant risks to federal computer systems and the operations and the infrastructures they support. GAO's evaluations show that federal computer systems are riddled with weaknesses that continue to put critical operations and assets at risk. GAO found weaknesses in following six areas: (1) security program management, (2) access controls, (3) software development and change controls, (4) segregation of duties, (5) operating systems controls, and (6) service continuity. Weaknesses in these areas place a broad range of critical operations and assets at risk for fraud, misuse, and disruption. Federal agencies have tried to address these problems, and many have good remedial efforts underway. However, these efforts will not be fully effective and lasting unless they are supported by a strong agencywide security management framework. Establishing such a management framework requires that agencies take a comprehensive approach that involves both (1) senior agency program managers who understand which aspects of their missions are the most critical and sensitive and (2) technical experts who know the agencies' systems and can suggest appropriate technical security control techniques.

Sep 28, 2017

Aug 3, 2017

Jul 27, 2017

Jul 26, 2017

May 31, 2017

May 23, 2017

Apr 4, 2017

Mar 30, 2017

Mar 28, 2017

Feb 14, 2017

Looking for more? Browse all our products here