As part of the Federal Information Security Modernization Act of 2014 (FISMA) legislation, the Treasury Inspector General for Tax Administration (TIGTA) is required to perform annual assessments of its agency’s information security programs and practices. The agency recently reported on its assessment of the effectiveness of the IRS’ information security program.
The agency’s cybersecurity program was considered not effective because three functions were not at an acceptable overall maturity level. Specifically, the IDENTIFY, PROTECT, and DETECT function areas were not effective. The remaining three function areas, “GOVERN, RESPOND, and RECOVER were rated effective.” The FISMA reporting metrics scoring methodology defines effective as being at a maturity Level 4, Managed and Measurable, or above.
The full report is available (PDF) on TIGTA’s website. The IRS’s Cybersecurity Program Was Not Effective for Fiscal Year 2026.
In Fiscal Year 2026, TIGTA tested the 20 core reporting metrics, 5 supplemental metrics, and 10 editorial metrics. The editorial metrics provide additional information regarding the effectiveness (whether positive or negative) of the IRS’s Cybersecurity Program areas.
The report found that, while the IRS has made some improvements over last fiscal year’s reported maturity level ratings, the Treasury Inspector General determined that the IRS needs to take further steps to improve its security program deficiencies. “IRS Cybersecurity management needs to fully implement all security program components in compliance with FISMA requirements. “
For example, 86 percent (6 out of 7) of the sampled information systems had critical vulnerabilities not remediated within 30 days, as required. If the IRS does not take steps to mitigate these deficiencies, taxpayer data could be vulnerable to inappropriate and undetected use, modification, or disclosure.
TIGTA said it does not make recommendations as part of its annual FISMA evaluation. It “only reports on the level of performance the IRS achieved using the guidelines for the applicable evaluation period.”
Sign in to get access to this free resource, and all of our whitepapers and reports.
Download this content today!
Register to get free access to this content, as well as newsletters, continuing education, podcasts, and more…
Register Now
Already registered? Click here to Log In
Read the FAQs
