U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

The IRS Has Improved Audit Trail Collection; However, Not All Audit Trail Data Are Being Collected and User Account Controls Need Improvement

Report Information

Date Issued
Report Number
2024-200-005
Report Type
Audit
Joint Report
No
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

The Chief Information Officer should implement a method of mapping OMB Memorandum M-21-31 requirements for all IRS systems to track and demonstrate compliance.

The Chief Information Officer should develop and implement a plan to ensure event logging data are collected from all systems that contain PII and FTI in accordance with IRM requirements.

The Chief Information Officer should direct a taxonomy reconciliation effort across the enterprise to standardize the IRS taxonomy to ensure the Next Generation ESAT program has a complete and accurate inventory of systems for its data repository.

The Chief Information Officer should ensure that the Next Generation ESAT program periodically validates receipt of required audit trail data from all source systems.

The Chief Information Officer should ensure that user inactivity on its data repository is monitored, and actions are taken on user accounts in accordance with the IRS Cloud Computing Security Policy IRM requirements.