GAO audit finds IRS security measures need work

July 24, 2019

Computer-security-_wallpapers4screen-dot-com_1366x768

The Internal Revenue Service and its Security Summit partners this summer launched a campaign to encourage tax professionals to review and upgrade their security systems.

But it looks like the IRS also needs to do some work, according to a recent Government Accountability Office (GAO) report.

IRS online option breach spurs inquiries: The GAO has been conducting audits on how the IRS manages its security since the agency sustained a data breach in 2015 of its Get Transcript online service.

That attempt by hackers exposed the data of around 104,000 taxpayers to potential identity thieves. The service was offline for more than a year as the IRS investigated and subsequently enhanced its online security measures.

Congress conducted several hearings into the online tool's breach. The Treasury Inspector General for Tax Administration (TIGTA) also investigated the issue.

In the GAO's latest inquiry, an audit of fiscal year 2018 IRS actions that was released July 18, investigators identified 14 new IRS security control shortfalls relating to information technology (IT) security.

GAO also noted that the IRS had not addressed 127 IT security recommendations that the watchdog agency previously issued.

Unsecure access issues: A key area of concern is IRS access controls, such as authentication and encryption.

Eight of the latest 14 security shortfalls identified by GAO relate to access management. An additional four fall in the configuration management. The final two areas where the IRS needs work are related to segregation of duties and a contingency plan deficiency.

Specifically, GAO found that the IRS:

  • Needs to implement several security measures designed to protect critical agency data from unauthorized use.
  • Did not use multifactor authentication for access to certain agency applications, a violation of policy from the Office of Management and Budget.
  • Did not enforce requirements for electronic signatures and password resets.
  • Had several cryptology gaps, including failure to encrypt certain servers and its email service, as well as not enforcing specific encrypted database connections.
  • Was not properly updating or upgrading out-of-date software.

The table below from the GAO report provides the exact numbers of pending security issues.

Status of GAO security recommendations to IRS_old and new 2019

Many, but not serious, risks: While all those items are disturbing, the good news is that the GAO determined the deficiencies are not great risks.

"We identified ongoing and new information system security control deficiencies that while not collectively considered a material weakness, were important enough to merit attention by those charged with governance of IRS and therefore represented a significant deficiency in IRS’s internal control over its financial reporting systems," wrote GAO Director of Financial Management and Assurance Cheryl E. Clark and Managing Director of Applied Research and Methods Nancy R. Kingsbury in a letter to IRS Commissioner Charles P. Rettig.

However, when it comes to interactions with and safeguarding taxpayers' information, any shortfall is concerning and attention is needed.

Old issues still open, new ones added: And the GAO noted that despite some actions cited in the earlier report that still need attention, the IRS has taken considerable steps to address its prior recommendations and has agreed to fix mistakes and flaws within its internal systems.

While the IRS is working on those, the GAO also gave the tax agency a new set of 20 security recommendations to resolve the new issues.

Congressional support and money required: We — government oversight agencies, lawmakers and all of us taxpayers — cannot let the IRS off the hook for security oversights.

It is, after all, our personal and financial data that Uncle Sam's tax collector gathers and should keep as safe as possible.

But there are extenuating circumstances.

The IRS in recent years has been working under severely restricted budgets. Its efforts to upgrade equipment, software and systems, as well as to catch tax and other crooks, particularly in recent years, have been seriously hindered by budget cuts and investigator attrition.

The new Taxpayer First Act will help in the security area somewhat. Several of the IRS reform measure's provisions are designed to discover and stop tax ID theft.

Such efforts, however, as well as upgrades to technology and systems take money.

Let's hope that under the recently reached federal budget agreement, Congress also will allocate some of the new money to the IRS for it to adequately address these old and new security concerns.

You also might find these items of interest:

Advertisements

 





 

Share:

The More Tax Posts tab at the top of this page will take you to, well, more tax posts. You also can search below for a tax topic. 

Latest Posts
6 tax moves to consider this June

June 3, 2026

Definitely take a break this June. But taxes don’t take vacations. So, you also should…

Read More
Tax Season 2026 Continues!

We made it. Tax Day 2025 is finally over. For most of us. When the filing season started on Jan. 26, millions who were expecting refunds filed immediately. Most of us got our returns to the Internal Revenue Service by April 15. But plenty of taxpayers also got extensions. They are looking at an Oct. 15 filing deadline.

Those procrastinating filers aren’t a problem. In fact, the IRS appreciates taxpayers who take time to fill out their 1040 forms correctly. It also is grateful that tax submissions are spread out a bit, especially now that the IRS is a leaner agency. Processing returns is easier when they arrive throughout the year instead of in massive bunches.

But enough about Uncle Sam’s tax collection issues. The focus now is on all y’all who filed for extensions, giving you another six months to complete your return. Since your new mid-October due date will be here before you know it, let’s get started now on meeting it.

The ol’ blog is here to help you finish up your extended Form 1040. You can start with January’s tax tips page, which has links to the rest of the year’s tips by-month collections. You also can peruse various tax categories for more tailored advice by clicking on the More Tax Posts drop-down menu at the top of this (and every) page.

And to make sure you don’t miss your new filing deadline, the count-down clock below will let you know just how much time you to file by Oct. 15. At the latest.e. (Note: I’m in the Central Time Zone, so adjust accordingly for where you live.)

Comments