Historically, civillian and national security-related IT systems have been governed by different sets of policies and procedures, said Gregory Wilshusen, Director of Information Security Issues at GAO. Both sets of guidance can cover similar topics and processes such as certification and accreditation and risk assessments.