ISR News: IRS On-Line Vulnerable
Excerpt from SANS.org
According to an audit report from the Treasury Inspector General for Tax Administration, the US Internal Revenue Service (IRS) launched an on-line tax filing system despite known security concerns. Although testing of the fourth release of the IRS Modernized e-File system revealed 13 security vulnerabilities, the system was launched in January 2007.
Among the concerns are lack of appropriate access controls on both the system and the database that stores filed documents, and the lack of a backup processing site should the main site be rendered unusable.
A second report, this one from the Government Accountability Office (GAO), indicated that the IRS has mitigated fewer than half of the 115 vulnerabilities it had noted in an earlier report. Among the GAO’s concerns are the lack of control over data access and the lack of encryption.
Filed under: Breach, D&O Liability, Financial, Government, Insider Threat, Sarbanes-Oxley, Uncategorized, hackers, identity-theft, malware, national security, privacy
Comments
Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!













