U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

The Remediation of Configuration Weaknesses and Vulnerabilities in the Registered User Portal Should Be Improved

Report Information

Date Issued
Report Number
2018-20-036
Report Type
Audit
Joint Report
Yes
Participating OIG
Treasury Inspector General for Tax Administration
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

The Chief Information Officer should ensure that the Enterprise Technology Implementation Division conducts a review of all internal risk-based decisions to ensure that: 1) at least a ***2*** exists for the vulnerabilities; 2) the *******2**********; and 3) the ***2*** accurately reflect the type of vulnerabilities that the technical team is addressing.

The Chief Information Officer should ensure that the contractor provides an accurate accounting of the status of vulnerabilities in reports that it shares with the IRS.

The Chief Information Officer should ensure that the contractor performs, at a minimum, an annual reconciliation of the IEP inventory in the CMDB to ensure that it includes the components outlined in the System Security Plan and ******2****** to support effective component accountability.

The Chief Information Officer should ensure that the Cybersecurity organization validates that the system inventory is reviewed as part of its next annual security assessment to ensure that it includes the component information deemed necessary as outlined in ********2******** and *******2*******.