Any organization creating, maintaining, using, or disseminating records of identifiable personal data must assure that data are used as intended and must take precautions to prevent misuse of the data. Additional comments in this area addressed the need for message authentication and nonrepudiation as security features. In summary, it was clearly the consensus that basic information security features should be required components that vendors build into information systems. Aside from virus checkers, few static audit tools exist in the market. Availability: assuring that authorized users have continued access to information and resources. This committee's goal of developing a set of Generally Accepted System Security Principles, GSSP, is intended to address this deficiency and is a central recommendation of this report. Integrity policies have not been studied as carefully as confidentiality policies. E    He made long-term plans, in one instance establishing a trapdoor that he used almost a year later. Enterprise networks will meet an emerging need: they will allow any single computer in any part of the world to be as accessible to users as any telephone. the need to ensure that employees of an organization are complying with the organization's policies and procedures. This policy means that the up time at each terminal, averaged over all the terminals, must be at least 99.98 percent. When rewards go only to visible results (e.g., meeting deadlines or saving costs), attention will surely shift away from security—until disaster strikes. System interconnection may even affect applications that do not involve communication at all: the risks of interconnection are borne not only by the applications they benefit, but also by other applications that share the same equipment. Computer measures that have been installed to guard integrity tend to be ad hoc and do not flow from the integrity models that have been proposed (see Chapter 3). A security policy is a concise statement, by those responsible for a system (e.g., senior management), of information values, protection responsibilities, and organizational commitment. In any particular circumstance, some threats are more probable than others, and a prudent policy setter must assess the threats, assign a level of concern to each, and state a policy in terms of which threats are to be resisted. Unlike proverbial lightning, breaches of security can be counted on to strike twice unless the route of compromise has been shut off. There are three types of information security threats: external threats, environmental or physical threats, and internal threats. Implicit in this process is management's choice of a level of residual risk that it will live with, a level that varies among organizations. When things go wrong, it is necessary to know what has happened, and who is the cause. It may be important to keep data consistent (as in double-entry bookkeeping) or to allow data to be changed only in an approved manner (as in withdrawals from a bank account). Big Data and 5G: Where Does This Intersection Lead? Seventy-three percent considered the capability to encrypt sensitive data to be mandatory, but one respondent was opposed to that feature because it could complicate disaster recovery (i.e., one might not be able to access such data in an emergency during processing at an alternate site). These comments are supportive of the GSSP concept developed by this committee. All of these involve physical elements and people as well as computers and software. The second, however, is a case in which need is not aligned with privacy; strong auditing or surveillance measures may well infringe on the privacy of those whose actions are observed. 