IRS's IG says agency IT staff too lax

Published 19 December 2008

IG report says IT staff were not always saving or reviewing system audit logs, and clock settings on some firewalls and routers did not comply with IRS rules, increasing likelihood of unauthorized intrusion

The U.S. Internal Revenue Service’s (IRSIT staff has not routinely checked its cybersecurity audit logs, according to a report released this week by the agency’s inspector general’s office. The IRS has effectively deployed intrusion detection systems at its Internet gateways, and it has used access controls for firewalls and routers, said the report, completed in July but released Monday. The agency’s IT staff, however, were not always saving or reviewing system audit logs, and clock settings on some firewalls and routers did not comply with IRS rules, the report said. “These weaknesses increase the likelihood that intruders from the Internet could gain access to sensitive taxpayer data residing on the IRS network without being detected,” the report said.

PCWorld’s Grant Gross writes that one IRS employee, the database administrator for routers, had access to router audit logs, even though IRS rules require that a worker outside the immediate IT staff responsible for routers have access for independent review, the report said. In addition, IRS IT staff did not save audit logs on two separate servers, as recommended in IRS guidelines.

The report, with large chunks redacted, recommends the IRS allow independent review of audit logs and establish procedures to save audit logs. It also recommended that the IRS regularly test its Internet gateways for compliance with standard security configurations. The IRS agreed with the recommendations, saying it planned to do bi-weekly compliance testing.

 The IRS’ parent agency, the Department of Treasury, received a failing grade for its 2007 cybersecurity efforts, according to a report card released in May. The annual report, released by the U.S. Congress, grades federal agencies’ compliance with the Federal Information Security Management Act, or FISMA.