U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Improvements Are Needed to Strengthen Electronic Authentication Process Controls

Report Information

Date Issued
Report Number
2016-20-082
Report Type
Audit
Joint Report
Yes
Participating OIG
Treasury Inspector General for Tax Administration
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

The Chief Information Officer should clarify IRS and contractor responsibilities related to preventing automated attacks, including tracking contractor activities and tools with respect to their responsibilities.

The Chief Information Officer should establish a process to monitor the results and effectiveness of controls to prevent/detect automated attacks.

The Chief Information Officer should ensure that Security Operations organization management supports and implements IRM policy with respect to security specialists' role in monitoring and analyzing audit trails.

The Chief Information Officer should ensure that the IRS provides security specialists with adequate tools and related training to perform analysis as described in audit plans.

The Chief Information Officer should implement enhancements to audit log analysis to provide for automated mechanisms to integrate audit review, analysis, and reporting processes and to correlate audit records across different repositories to gain organization-wide situational awareness.