U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Software Version Control Management Needs Improvement

Report Information

Date Issued
Report Number
2019-20-031
Report Type
Audit
Joint Report
Yes
Participating OIG
Treasury Inspector General for Tax Administration
Agency Wide
Yes (agency-wide)

Recommendations

The Chief Information Officer should create an enterprise-wide, integrated structure to centralize commercial-off-the-shelf software version tracking, currency, and management to include documenting roles and responsibilities.

The Chief Information Officer should update policies and procedures to manage mainframe, server, and workstation software assets using industry best practices, including identifying, prioritizing, and removing outdated software when newer versions are installed.

The Chief Information Officer should create and execute a plan to periodically monitor and compare software running on the enterprise against the Enterprise Architecture ESP Product Catalog for accuracy.

The Chief Information Officer should remove unauthorized software or update the ESP Product Catalog to reflect the correct information, if warranted.

The Chief Information Officer should document and approve risk acceptance to continue using older versions of software (i.e., sunset, archived/retired).