Lessons learned in the DOE Computer Security Enhancement Review Program
W.J. Hunteman · 1989
During the last 4 years, DOE has made the most detailed and extensive computer security self-evaluation of any US government organization. The breadth and depth of the examination have revealed some problems. Few of the problems are major; most are procedural, some administrative, a few technical, and almost none systemic. This report documents the lessons learned from one part of the evaluation process.