The IRS Needs to Improve Its Database Vulnerability Scanning and Patching Controls
Report Information
Date Issued
September 30, 2022
Report Number
2022-20-065
Report Type
Audit
Joint Report
Yes
Participating OIG
Treasury Inspector General for Tax Administration
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0
Recommendations
****************2**************** is performed on all IBM mainframe databases.
Ensure that IRM 10.8.33 is updated to accurately reflect the Mainframe Product Security Requirements Guide.
The Chief Information Officer should ensure that the ISSOs have a formal process for recommending approval or disapproval of policy deviations to ensure that the operational security posture is consistent with current system security policy. This would include monitoring compliance with system security policy and providing guidance and recommendations to correct deficiencies.
Ensure that privileged vulnerability scans are performed on the cloud systems when possible.
Ensure that the IRS provides oversight to cloud service providers and obtains detailed scan results so the IRS can assess the database vulnerabilities.
