Amid a year of attempted and successful breaches of IRS systems, the tax agency has yet to fully implement a number of needed security controls despite prior warnings, according to a recent report from the Government Accountability Office.
While IRS has improved its cybersecurity posture overall, GAO auditors found that agency networks continue to suffer from a lack of access controls, which could allow unauthorized users to gain access to sensitive taxpayer information.
Report: IRS Needs to Further Improve Controls Over Financial and Taxpayer Data
This was the case with the “Get Transcript” application, which hackers were able to dupe using social engineering and widely available information on taxpayers. Once past the knowledge-based security measures, they were able to compromise the information of more than 700,000 taxpayer accounts.
“Our previous reports — and those by federal inspectors general — describe persistent information security weaknesses that place federal agencies, including IRS, at risk of disruption, fraud or inappropriate disclosure of sensitive information,” GAO notes in its report. “IRS had implemented numerous controls over its systems. However, it had not always effectively implemented access and other controls.”
Specifically, the GAO found IRS failed to properly secure its systems in six areas:
- Implementing controls for identifying and authenticating users, such as applying proper password settings.
- Appropriately restrict access to servers.
- Ensure that sensitive user authentication data are encrypted.
- Audit and monitor systems to ensure compliance with agency policies.
- Ensure access to restricted areas was appropriate.
- Leaving unpatched and outdated software exposed to known vulnerabilities.
“The agency had a comprehensive framework for its program, such as assessing risk for its systems, developing security plans, and providing employees with security awareness and specialized training,” according to the report. “However, aspects of its program had not yet been effectively implemented.”
For example, GAO found that the passwords used to access key systems — including procurement, access request and tax return processing — were easy to guess and left vulnerable to malicious actors.
Similarly, employees who were given access generally had more than they needed, violating the best practice of “least privilege access.” While it might seem minor, granting too much access to authorized users is part of what allowed the massive hack of the Office of Personnel Management to occur.
GAO added two recommendations to an outstanding list of unresolved issues, bringing the total number to 45. The specifics of those recommendations were not released publicly but included in an additional report with limited distribution.
“Until IRS takes additional steps to address unresolved and newly identified control deficiencies and effectively implement elements of its information security program, including, among other things, updating policies, test and evaluation procedures and remedial action procedures, its financial and taxpayer data will remain unnecessarily vulnerable to inappropriate and undetected use, modification or disclosure,” according to the report.
IRS Commissioner John Koskinen said the agency is reviewing the specific recommendations to make sure they include sustainable solutions but agreed with GAO’s comments in general.




