It is a well-established fact that the majority of cyber security risks are in fact a result of human error, and the GAO's information security report highlights that access controls, which include boundary protection, authorization, identity authentication, auditing and monitoring and physical security, were weak in all 24 agencies.