The U.S. Internal Revenue Service remains vulnerable to cybersecurity threats, in particular insider threats that continue to jeopardize the confidentiality of taxpayer information according to a report (PDF) released by the U.S. Government Accountability Office Friday.
The report points out that the IRS doesn't always enforce strong password management, authorize user access, encrypt sensitive data, effectively monitor mainframe changes or physically protect its computer resources.
The IRS collected about $2.7 trillion in taxes in 2007/08 and relies extensively on computerized systems; systems that are still vulnerable to misuse. While the IRS has corrected 49 of the 115 security issues found by the GAO during its last IRS audit, it's still not enough. "Despite IRS's progress, information security control weaknesses continue to jeopardize the confidentiality, integrity, and availability of financial and sensitive taxpayer information," the GAO report said.
According to the report, the key reason for these weaknesses is that the IRS has not yet fully implemented an agencywide information security program; specifically, that the IRS does not review risks annually, test for controls, or always validate the effectiveness of corrective measures.
"Until IRS takes these steps, financial and taxpayer information is at increased risk of unauthorized disclosure, modification, or destruction, and the agency's management decisions may be based on unreliable or inaccurate financial information," the report said.
IRS Commissioner Douglas H. Shulman said the agency will continue working with GAO and will create an action plan to address each of the recommendations in the report.
Comments
Subscribe to comments for this post OR Subscribe to comments for all ReadWriteWeb posts
Well this is priceless. Here we have one of the largest government agencies shouting beware of E-filing Sites and advising "How to Choose a Tax Preparer and Avoid Preparer Fraud” and our information may be most vulnerable in their hands.
Can you imagine, I am scrupulous about conducting my financial transactions at secure sites almost all have Extended Validation SSL authentication certificates. (Green url bar along with keypad lock), now my ultimate concern is with my own government, who is protecting me?