Information Systems:

Agencies Overlook Security Controls During Development

IMTEC-88-11S: Published: May 31, 1988. Publicly Released: May 31, 1988.

Additional Materials:


Office of Public Affairs
(202) 512-4800

GAO provided a supplement to its report on agencies' development of automated systems. GAO provided information regarding the model it used in determining that federal agencies it reviewed did not meet federal criteria or practice sound system development methods for successfully incorporating appropriate security controls during their development of automated information systems.

GAO discussed the model's: (1) construction, which it based on federal guidance and standards and generally accepted practices of software engineering; and (2) sub-activities, including the initiation, definition, design, construction, integration, installation, and test phases. GAO also discussed the potential effects of agencies not performing security activities during each of the model's systems development phases.

Mar 7, 2018

Feb 6, 2018

Sep 28, 2017

Aug 3, 2017

Jul 27, 2017

Jul 26, 2017

May 31, 2017

May 23, 2017

Apr 4, 2017

Mar 30, 2017

Looking for more? Browse all our products here