Report: IRS System Weaknesses Put Public Data at Risk

Government Accountability Office says the IRS must remedy unencrypted networks, outdated software, faulty access control protocols.

by / April 1, 2011
Pedro Nunes

Vulnerabilities in IRS tax and financial processing systems endanger the private citizen information the systems contain, the Government Accountability Office (GAO) claimed in a March report.

The GAO identified 37 new weaknesses from fiscal 2010 when performing an annual audit of IRS systems. The findings were reported in IRS Needs to Enhance Internal Control over Financial Reporting and Taxpayer Data.

The new deficiencies cited by the GAO included unencrypted networks, outdated software, faulty access control protocols and employees with unnecessary access privileges.

“Our bottom line is that the IRS still needs to enhance the internal controls over their financial reporting and taxpayer data,” said Greg Wilshusen, the GAO’s director of information security issues. “We have found weaknesses in many of the areas in which we looked and the controls that we tested, and we found that these weaknesses continue to place financial and taxpayer information at risk.”

The situation for the IRS might actually be improving. Wilshusen said that the agency found 88 weaknesses two years ago. But he said the IRS had only remediated 23 of those previous 88 issues.

“They indicated they had corrected 39 of those [88 issues], and they told us which ones,” Wilshusen said. But the GAO claims that, in fact, 16 of the “corrected” vulnerabilities still remain. “That speaks to flaws in IRS’ verification and validation processes for assuring corrective actions.”

The IRS also has faulty procedures when it comes to testing the strength of internal policies and procedures. “We found that their tests were not comprehensive and that IRS did not identify many of the weaknesses that we identified during our testing,” Wilshusen said.

But Wilshusen did mention some positive steps the IRS has taken. The agency has provided security awareness training to all employees, including specialized training to those with significant security responsibilities.

The IRS didn't return calls for comment about the GAO's report.

Hilton Collins

Hilton Collins is a former staff writer for Government Technology and Emergency Management magazines.

Platforms & Programs