Most Popular Stories
- Top FAA execs lack institutional knowledge, says official; agency must be prepared for cuts
- Air traffic control training gaps will be exacerbated by NextGen, says OIG
- Agencies plan for governmentwide FOIA portal
- FAA reauthorization would create NextGen czar UPDATED
- Obama administration announces immigrant visa waiver change
Events
- TECHEXPO Top Secret Career Fair
February 29, 2012 — Colorado Springs, CO 10am - 3pm - IBM Global Business Services Career Expo
February 16, 2012 — Linthicum Heights, MD 10am - 3pm - AFCEA Bethesda Monthly Breakfast Series
February 24, 2012 — Bethesda, MD - Learn With Your Peers at the Federal Senior Management Conference
April 15-18 — Cambridge, MD
Sponsored Links
HOT TOPICS >> Cloud computing | Cybersecurity | Gov 2.0 | Fiscal 2012 | Mobile | Transparency | GAO reports
AGENCY NEWS >> Defense | NASA | Homeland Security | NIST | OMB | Veterans Affairs | NARA | GSA
Latest News
Free Newsletter
About | View Sample | Privacy
Popular Topics
Whitepapers
- Cloud Computing: Threat or opportunity for VARs and MSPs? Special focus on cloud collaboration and messaging
- Business Intelligence: It's All in the Data
- Innovative Solutions for Database and DBA Management
- Efficiency On Demand
- IMPROVING THE MANAGEMENT OF FEDERAL GOVERNMENT IT ASSETS THROUGH BETTER COMMUNICATION WITH THE IT INDUSTRY
- Virtual Game Changer
IRS needs better grip on contractors with taxpayer data access, says TIGTA
The Internal Revenue Service isn't quite sure how many private sector employees it should review each year for security purposes because of their access to taxpayer data, according to a new audit.
The IRS--like much of the government--relies extensively on companies in support roles. Accenture operates and maintains IRS.gov. Northrop Grumman provides technology that scans tax returns. AT&T delivers telework networking.
However, when the IRS infrastructure security and reviews office each year has wanted to conduct security checks of contractors working on those support IT systems, it left it up to the companies to identify to the IRS which employees worked on those systems, according to a new report from the Treasury Inspector General for Tax Administration, based on an investigation conducted from June 2009 through January 2010.
Based on that data call, the IRS then prepared a list of contractors targeted for security review, based in part to the type of tax data processed by the contractor.
It has not been an effective process, and it missed two individuals who should have been reviewed, auditors say. Instead, the IRS should have its own IT system for identifying which private sector employees in proximity to the IRS should undergo annual review, a recommendation that the IRS says it will implement.
The audit also faults the IRS for not following cybersecurity reviews of contractor systems with a tracking document known as a "Plan of Action and Milestones," which is required under the Federal Information Security Management Act and is known mostly by its acronym, POA&M.
The IRS did review contractors IT systems and did identity correction actions along with planned implementation dates, but did not develop POA&Ms for the weaknesses, the audit states.
When asked why, the IRS told auditors that it did not consider the systems in question because they were not FISMA-reportable.
"While there might be confusion over what is or is not FISMA reportable, we believe the approach for tracking and monitoring security weaknesses should apply regardless," auditors wrote. In a review of eight contractor facility systems, auditors found 24 repeat weaknesses left over from fiscal 2008.
The IRS will start to develop POA&Ms for previously uncovered contractor IT systems, the agency promised auditors.
For more:
- read TIGTA audit 2010-20-051 (.pdf)
Related Articles:
Prisoners fraudulently claim $9.1 million in homebuyer tax credits
TIGTA finds IRS configuration management lacking in tax scofflaw contact system
TIGTA: IRS should chill
Related Stories
- NRC cybersecurity hole remediation needs work, says audit firm
- DOT continues to lag on resolving cybersecurity problems
- GAO makes 105 recommendations to patch IRS information security holes
- IRS's 'Workforce of Tomorrow' draws TIGTA security concerns
- IRS has cybersecurity material weakness, says GAO
- GSA not implementing cybersecurity policies, says IG
- TIGTA: 'Significant' risks remain with IRS modernization
- IRS closed IT security component before corrections were complete, says IG
- NASA CIO unaware of cybersecurity holes, says IG
- High-risk vulnerabilities found in key US-CERT system
Home
| Subscribe | Advertise | Mobile Edition | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |


