U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Substantial Progress Has Been Made in Implementing the Insider Threat Capability, but Improvements Are Needed

Report Information

Date Issued
Report Number
2020-20-043
Report Type
Audit
Joint Report
Yes
Participating OIG
Treasury Inspector General for Tax Administration
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

The Chief Information Officer should ensure that the User Behavior Analytics Capability (UBAC) project implementation plan includes actions to determine and assess the risk posture of high value assets. To efficiently complete these actions, the UBAC function should obtain and review the documentation of all high value assets and related risk assessments of those assets performed by other IRS programs, if available. The identified high value assets¿ risks should be addressed as part of the capability implementation.

The Chief Information Officer should ensure that status reports align with the National Insider Threat Task Force recommendations and include sections to address program improvement and major impediments or challenges.

The Chief Information Officer should ensure that the UBAC project implementation plan includes the National Insider Threat Task Force's recommended training for UBAC personnel. In addition, the IRS should document all UBAC training efforts and, at least annually, ensure that all UBAC personnel have completed the required training.