Oversight

GAO: IRS has information security control weaknesses

gold shield on top of computer code

The Internal Revenue Service continues to have weaknesses in information security control that the Government Accountability Office fears could affect the confidentiality, integrity and availability of financial and sensitive taxpayer data.

An April 8 GAO report found that although the IRS has improved on information security control and internal control over financial reporting, significant risks remain.

The agency has failed to consistently install the appropriate patches on all databases and servers to protect against known vulnerabilities, GAO found, and also failed to sufficiently monitor database controls and appropriately restrict access to its mainframe environment. The IRS has also allowed individuals to make changes to mainframe data processing without following required procedures.

“Without effective audit and monitoring, IRS’s ability to establish individual accountability, monitor compliance with security and configuration management policies, and investigate information systems security violations is limited,” the report reads.

GAO found one of the main reasons for the ongoing weaknesses is the failure of the IRS to implement portions of its information security program, which have not always functioned as intended, such as the agency’s testing procedures for financial reporting systems.  

GAO also provided three recommendations for the IRS to fix its weaknesses: update access request procedures to ensure appropriate access privileges; update information policies and procedures; and develop a plan to address the known and newly identified vulnerabilities.

About the Author

Mike Cipriano is a GCN editorial intern, and also writes occasionally for FCW. Connect with him on Twitter: @mikecip07.

Featured

  • Defense
    Ryan D. McCarthy being sworn in as Army Secretary Oct. 10, 2019. (Photo credit: Sgt. Dana Clarke/U.S. Army)

    Army wants to spend nearly $1B on cloud, data by 2025

    Army Secretary Ryan McCarthy said lack of funding or a potential delay in the JEDI cloud bid "strikes to the heart of our concern."

  • Congress
    Rep. Jim Langevin (D-R.I.) at the Hack the Capitol conference Sept. 20, 2018

    Jim Langevin's view from the Hill

    As chairman of of the Intelligence and Emerging Threats and Capabilities subcommittee of the House Armed Services Committe and a member of the House Homeland Security Committee, Rhode Island Democrat Jim Langevin is one of the most influential voices on cybersecurity in Congress.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.