IRS Is Not Keeping Up to Date on Data Security
Cross References
TIGTA Report No. 2022-20-051, September 21, 2022 The Taxpayer Digital Communications (TDC) platform enables faster communication as well as offers taxpayers and their authorized representatives the ability to securely send and receive electronic messages and documents to and from IRS agents and customer service representatives. Without effective security and access controls, the TDC platform is susceptible to data loss and manipulation as well as unauthorized access and disclosure of taxpayer data. It is also vulnerable to human errors or actions committed with malicious intent. People acting with malicious intent can use their accesses to obtain sensitive information, commit fraud and identity theft, disrupt operations, and launch attacks against the IRS.
The eGain Corporation is the dedicated managed service provider (MSP) for the TDC platform. The TDC platform, including its 12 installations in production, are stored on the eGain platform in a Federal Risk and Authorization Management Program authorized Amazon Web Services GovCloud.
The Treasury Inspector General for Tax Administration (TIGTA) recently did an audit of the IRS and the TDC platform. It found that production servers on which the TDC platform resides are encrypted to protect TDC installation data, and configuration settings for password length and complexity are in compliance with federal and local requirements. However, Federal Risk and Authorization Management Program security reviews for continuous monitoring are not being conducted by the IRS to ensure that the Amazon Web Services GovCloud’s security posture remains sufficient for the TDC platform. Two critical and three high severity rated antivirus software releases were not installed on the TDC platform, and it was using an outdated version of the antivirus software for approximately one year. TIGTA reviewed 175 security vulnerabilities and determined that the eGain MSP did not timely remediate four (2.3 percent) critical security vulnerabilities. The remediation time ranged from 16 to 42 calendar days. In addition, audit trails are not being reviewed. The TDC platform has 3,939 distinct total users; however, 681 users were not authorized to have access to the TDC platform, and 498 users were authorized but did not have access to the TDC platform. Of the 3,258 authorized users, 735 users were not timely recertified. Finally, 1,237 user accounts were not timely disabled, quarantined, or removed due to inactivity, of which 646 user accounts were never logged in.
IRS Is Not Keeping Up To Date on Data Security continued
TIGTA made 11 recommendations to the Chief Information Officer. They include ensuring that the standard operating procedures are updated to require continuous monitoring security reviews and the security reviews are conducted; eGain MSP personnel timely upgrade antivirus software in accordance with requirements; users are both authorized and have access to the TDC platform; and a process is developed to timely identify, quarantine, and remove user accounts for inactivity in accordance with requirements. The IRS agreed with all 11 recommendations. The IRS plans to update its standard operating procedures to conform to TIGTA recommendations. To read the full report, visit the TIGTA website at: www.treasury.gov/tigta/