| |
| | GAO-03-233, Critical Infrastructure Protection: Challenges for Selected Agencies and Industry Sectors |
 | | Once these assets and dependencies are identified, further steps will be necessary, such as conducting or updating vulnerability assessments, managing identified vulnerabilities, and ensuring that these assets are appropriately considered in planning for the continuity of essential agency operations. |
 | | Once critical assets and their associated dependencies are identified, the agencies are to assess their vulnerability to physical or cyber attack and, if vulnerabilities are found, to develop and implement plans to manage the risks posed by potential attacks to the performance of essential functions and services. |
 | | Although federal continuity-of-operations guidance does not specify how often plans should be updated, plans over 2 years old predate the terrorist attacks that occurred on September 11, 2001, and for Energy and EPA, predate the identification of their tentative critical assets. |
| www.gao.gov /htext/d03233.html (13787 words) |
|