Free Site Registration


Software Patch Management an Issue at IRS

Print
Email
Reprints
Washington, D.C. (November 2, 2012)

By Daniel Hood

The Internal Revenue Service has made progress in automating installation and monitoring in a large segment of its computers, but it hasn't yet implemented key patch management policies and procedures, according to a new report by the Treasury Inspector General for Tax Administration.

J. Russell George

Properly installing software patches to address vulnerabilities is an important element in mitigating security risks, and requires strong policies to ensure patches are installed quickly to avoid giving attackers opportunities to exploit weaknesses in software, and to deny them potential access to sensitive data.

TIGTA initiated an audit to evaluate the IRS's security patch management process, and found some ground-level progress in automating the installation and monitoring of patching, it still had work to do on other levels, such as completing a complete and accurate inventory of all its technology assets (so it knows which systems need patching), and to improve systems to make sure patches are installed on a timely basis.

"Although the IRS has made some progress, we found that it has not implemented controls to secure unsupported operating systems," said Inspector General J. Russell George. "The IRS needs enterprise-level oversight and leadership to complete the implementation of its standardized patch management program and to reduce associated risks."

TIGTA also recommended the complete deployment of an automated asset discovery tool, the construction of an accurate and complete inventory of information technology assets, an enterprise-wide approach to buying tools to avoid redundancy and excessive cost, and complete implementation of controls to ensure that unsupported operating systems are not putting the IRS at risk.

The IRS agreed with TIGTA's recommendations and planned appropriate corrective actions for seven of the eight recommendations. Although the IRS agreed with the intent of the recommendation to hold system owners accountable for patching computers within prescribed time frames, it stated that its existing procedures addressed this recommendation and planned no corrective actions.

0 Comments

Be the first to comment on this post using the section below.

Add Your Comments...

Already Registered?

If you have already registered to Accounting Today, please use the form below to login. When completed you will immeditely be directed to post a comment.

 

Follow Accounting Today
Advertisement
Advertisement

Women in Accounting: Where are the Leading Ladies?

May 17, 2013

Marcum’s Nanette Lee Miller and Janis Cowhey McDonagh sat down with managing editor Tamika Cody to discuss some of the obstacles women in the accounting profession face when trying to make their way into leadership positions.

IMA’s Jeff Thomson on the Role and Skills of Management Accountants

May 8, 2013

Institute of Management Accountants president and CEO Jeffrey Thomson discusses why accounting students should consider management accounting as a career, and the IMA's partnership with John Wiley & Sons.

Breaking out of Molds to Get Ahead

May 6, 2013

ConvergenceCoaching partner Jennifer Wilson talks with Accounting Today senior editor Danielle Lee about how female accountants can position themselves better for a promotion at their firms.

Advertisement

SLIDE SHOW

Top 10 Tech Initiatives -- 2013

May 5, 2013

The AICPA's annual list of IT priorities for accounting firms.

Tax Stats: May 2013

April 30, 2013

Our monthly collection of statistics from the world of tax.

10 Biggest Estate Planning Mistakes

April 29, 2013

Help your clients avoid these common pitfalls.

Common E-mail Security Mistakes

April 23, 2013

These five bad habits can make your confidential information -- and that of your clients -- easy to steal.

The Art of the Tax Cartoon

April 9, 2013

A selection of tax cartoons from Philly tax firm Drucker & Scaccetti's 'Finding Humor in Taxes' exhibit.

Advertisement
Advertisement
Advertisement