U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

The Bring Your Own Device Program’s Security Controls Need Improvement

Report Information

Date Issued
Report Number
2019-20-046
Report Type
Audit
Joint Report
Yes
Participating OIG
Treasury Inspector General for Tax Administration
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

To reduce the risk to the BYOD program, the Chief Information Officer should identify a viable solution or take mitigation actions to prevent data leakage through the screen capture function on personally owned iPhones in the BYOD program.

To reduce the risk to the BYOD program, the Chief Information Officer should coordinate with other IRS offices, such as Labor Relations, to ensure that the employee's manager considers employee Personally Identifiable Information and Internal Revenue Code Section 6103 violations prior to approving participation.

The Chief Information Officer should ensure that the IRM requirement is met and vulnerabilities found on BYOD servers are timely remediated.

The Chief Information Officer should ensure the retention of BYOD program application audit logs for the appropriate period and periodic review of the application audit logs by an independent source.

The Chief Information Officer should ensure the creation and review of an application change log for BYOD program application configuration changes.