The Internal Revenue Service's Cybersecurity Program was not effective because three of the six functions (identify, protect and detect) did not meet the required maturity level, according to a new report.
The
Under the Federal Information Security Modernization Act of 2024, inspector general offices such as TIGTA are required to annually assess their agencies' information security programs and practices. According to FISMA, functions are considered to be effective at Maturity Level 4, Managed and Measurable, or above. FISMA focuses on improving oversight of federal information security programs and facilitating progress in correcting agency information security weaknesses.
In fiscal year 2025, TIGTA noted, the IRS collected nearly $5.3 trillion in gross taxes and processed 271.4 million tax returns and other forms, representing a substantial amount of taxpayer personal and financial information.
"As the custodian of taxpayer information, the IRS is responsible for implementing appropriate security controls to protect the confidentiality of this sensitive information against unauthorized access or loss," said the report. "Within the IRS, the Information Technology organization's Cybersecurity function protects taxpayer information and electronic systems and services from internal and external, cybersecurity related threats. As threats grow in scale and sophistication, cybersecurity is critical to mission delivery and public trust."
TIGTA acknowledged the IRS has made some improvements over last fiscal year's reported maturity level ratings but determined that the IRS needs to take further steps to improve its security program deficiencies. It said IRS cybersecurity management needs to fully implement all security program components in compliance with FISMA requirements.
The IRS disagreed with TIGTA's assessment on the maturity of its Information Security Continuous Monitoring Program.
"The IRS remains committed to strengthening its cybersecurity program and appreciates TIGTA's feedback for continued improvement," wrote IRS chief information officer Kaschit Pandya in response to the report. "The IRS will continue enhancing its governance documentation and program artifacts to improve traceability and transparency."
The IRS








