IRS cybersecurity judged ineffective

IRS headquarters in Washington, D.C.
Andrew Harrer/Bloomberg

The Internal Revenue Service's Cybersecurity Program was not effective because three of the six functions (identify, protect and detect) did not meet the required maturity level, according to a new report. 

Processing Content

The report, released Friday by the Treasury Inspector General for Tax Administration, found the remaining three functions (govern, respond and recover) were effective, however. Although the IRS improved some of its maturity ratings, security deficiencies remain. For example, six of the seven sampled systems (86%) had critical vulnerabilities that weren't remediated within the required 30 days, leaving taxpayer data vulnerable to inappropriate or undetected use, modification or disclosure.

Under the Federal Information Security Modernization Act of 2024, inspector general offices such as TIGTA are required to annually assess their agencies' information security programs and practices. According to FISMA, functions are considered to be effective at Maturity Level 4, Managed and Measurable, or above. FISMA focuses on improving oversight of federal information security programs and facilitating progress in correcting agency information security weaknesses. 

In fiscal year 2025, TIGTA noted, the IRS collected nearly $5.3 trillion in gross taxes and processed 271.4 million tax returns and other forms, representing a substantial amount of taxpayer personal and financial information. 

"As the custodian of taxpayer information, the IRS is responsible for implementing appropriate security controls to protect the confidentiality of this sensitive information against unauthorized access or loss," said the report. "Within the IRS, the Information Technology organization's Cybersecurity function protects taxpayer information and electronic systems and services from internal and external, cybersecurity related threats. As threats grow in scale and sophistication, cybersecurity is critical to mission delivery and public trust."

TIGTA acknowledged the IRS has made some improvements over last fiscal year's reported maturity level ratings but determined that the IRS needs to take further steps to improve its security program deficiencies. It said IRS cybersecurity management needs to fully implement all security program components in compliance with FISMA requirements. 

The IRS disagreed with TIGTA's assessment on the maturity of its Information Security Continuous Monitoring Program.

"The IRS remains committed to strengthening its cybersecurity program and appreciates TIGTA's feedback for continued improvement," wrote IRS chief information officer Kaschit Pandya in response to the report. "The IRS will continue enhancing its governance documentation and program artifacts to improve traceability and transparency."

The IRS lost about 25% of its information technology staff last year during cutbacks at the federal government, according to an earlier TIGTA report from last October.


For reprint and licensing requests for this article, click here.
Tax Technology IRS TIGTA Cyber Security
MORE FROM ACCOUNTING TODAY
Load More