U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Information Technology Risks Are Identified, Assessed, and Reported, but Mitigation Documentation and Oversight Need Improvement

Report Information

Date Issued
Report Number
2019-20-052
Report Type
Audit
Joint Report
Yes
Participating OIG
Treasury Inspector General for Tax Administration
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

The Chief Information Officer should require all IT organization functions (except the Cybersecurity function) to record information technology risks in the ITRAC system.

The Chief Information Officer should require detailed descriptions of the risk mitigation plans, mitigation activities, and closure rationale be captured and closure documentation be uploaded into the ITRAC system for the IT organization function and program risks, as applicable.

The Chief Information Officer should require periodic review of the risk descriptions and documentation uploaded into the ITRAC system to ensure that the information is appropriate, current, complete, and accurate.

The Chief Information Officer should reassess risk quarterly, or on a reasonable basis within the year as determined by the risk owner, for all accepted unmitigated risks to ensure that acceptance remains management's preferred response.