Friday, September 18, 2026

Just in: Our annual assessment of IRS's cybersecurity program Inbox Treasury Inspector General for Tax Administration Unsubscribe 6:30 AM (4 hours ago) to me TIGTA The IRS’s Cybersecurity Program Was Not Effective for Fiscal Year 2026 Why did we do this audit? Under the Federal Information Security Modernization Act of 2024 (FISMA), Offices of Inspector General (like us) are required to annually assess their agencies’ information security programs and practices. What did we find? The IRS’s Cybersecurity Program was not effective because three of the six functions (IDENTIFY, PROTECT, and DETECT) did not meet the required maturity level. The remaining three (GOVERN, RESPOND, and RECOVER) were effective. Under FISMA, functions are effective at Maturity Level 4, Managed and Measurable, or above. Although the IRS improved some maturity ratings, security deficiencies remain. For example, six (86 percent) of seven sampled systems had critical vulnerabilities that were not remediated within the required 30 days, leaving taxpayer data vulnerable to inappropriate or undetected use, modification, or disclosure. Read the full report

Just in: Our annual assessment of IRS's cybersecurity program Inbox Treasury Inspector General for Tax Administration Unsubscribe 6:30 AM (4 hours ago) to me TIGTA The IRS’s Cybersecurity Program Was Not Effective for Fiscal Year 2026 Why did we do this audit? Under the Federal Information Security Modernization Act of 2024 (FISMA), Offices of Inspector General (like us) are required to annually assess their agencies’ information security programs and practices. What did we find? The IRS’s Cybersecurity Program was not effective because three of the six functions (IDENTIFY, PROTECT, and DETECT) did not meet the required maturity level. The remaining three (GOVERN, RESPOND, and RECOVER) were effective. Under FISMA, functions are effective at Maturity Level 4, Managed and Measurable, or above. Although the IRS improved some maturity ratings, security deficiencies remain. For example, six (86 percent) of seven sampled systems had critical vulnerabilities that were not remediated within the required 30 days, leaving taxpayer data vulnerable to inappropriate or undetected use, modification, or disclosure. Read the full report

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.

What Lies Inside the Unfound Virginia Vault?

https://youtu.be/UveIFufST8c?si=3zfNuw4t-Qy7FLHg