Information Systems
Agencies Overlook Security Controls During Development Gao ID: IMTEC-88-11S May 31, 1988GAO provided a supplement to its report on agencies' development of automated systems. GAO provided information regarding the model it used in determining that federal agencies it reviewed did not meet federal criteria or practice sound system development methods for successfully incorporating appropriate security controls during their development of automated information systems.
GAO discussed the model's: (1) construction, which it based on federal guidance and standards and generally accepted practices of software engineering; and (2) sub-activities, including the initiation, definition, design, construction, integration, installation, and test phases. GAO also discussed the potential effects of agencies not performing security activities during each of the model's systems development phases.