5.1.25 IDRS and Data Security for Collection

Manual Transmittal

August 24, 2016

Purpose

(1) This transmits a revised IRM Part 5.1.25, Field Collecting Procedures, IDRS and Data Security for Collection.

Background

IRM 5.1.25, IDRS and Data Security for Collection, further defines requirements found in IRM 10.8.1, Information Technology (IT) Security, Policy and Guidance and IRM 10.8.34, Information Technology (IT) Security, IDRS Security Controls. In the event of a discrepancy, information in Part 10 takes precedence.

Material Changes

(1) This IRM contains grammatical changes throughout.

(2) This IRM’s title was changed to IDRS and Data Security for Collection to align with new organizational name changes.

(3) This IRM title and text are updated to reflect organizational changes following the FY2015 Compliance Realignment.

(4) All references to the Weekly Sensitive Access (Other/Spouse) report have been changed throughout to match the report title in IDRS Online Report Services (IORS).

(5) IRM 5.1.25.2.1(2)c, Managers of IDRS Users, expanded to include the limited role of bargaining unit Alternate USRs.

(6) IRM 5.1.25.3 (4), IDRS User Support, updated table for Modify User Profile to Add/Delete security command codes to coordinate with the primary Data Security Analyst.

(7) IRM 5.1.25.3.2.2, Request for Uncommon Command Codes, updated to include additional position titles reflecting the expanded customer base.

(8) IRM 5.1.25.4.1.3.2, Weekly Sensitive Access (Other/Spouse) was updated to; clarify actionable items on the report, include additional applications, add exception for Centralized Campus Operations who receive external phone calls which may not be reviewed remotely, and incorporated terms common to the expanded customer base.

(9) IRM 5.1.25.4 (2), Security Command Code Usage, added exception for Centralized Campus Operations.

(10) IRM 5.1.25.6 (3) b, Command Code Activity, added exception for Centralized Campus Operations.

(11) IRM 5.1.25.6 (6), Security Audit and Analysis Systems, changed the term Field Collection databases to read inventory applications

(12) Exhibit 5.1.25-1, added three acronyms: ALS (Automated Lien System), AMS Accounts Management Services) and AOIC (Automated Offers in Compromise).

(13) Exhibit 5.1.25- 2, Changed title to Common Command Codes - SB/SE Collection Operations and Operations Support, expanded the tables to encompass variances between Collection Operations (Field Groups versus Centralized Campus Operations) and Operation Support.

Effect on Other Documents

This IRM supersedes IRM 5.1.25 dated December 11, 2014.

Audience

Small Business/Self-Employed, Collection Operations and SB/SE Operation Support Employees.

Effective Date

(08-24-2016)

Related Resources

Website References:

  • General UNAX Overview and Resources

  • IDRS Online Report Services (IORS)

  • IDRS Unit and USR Database (IUUD)

  • IDRS Command Code Job Aid

  • Collection Information Technology & Security (CITS) SharePoint

.

Samuel Perdue
Director, Quality and Technical Support

Overview

  1. This IRM section provides policies and guidance to SB/SE Collection Operations and Operations Support Managers and Data Security Analysts (DSA) to carry out their respective responsibilities regarding security of the Integrated Data Retrieval System (IDRS) and other applications that contain taxpayer data.

  2. This functional IRM expanded the audience to include Small Business/Self Employed, Collection Operations Managers, Operation Support Managers and Data Security Analysts. The audience includes the following functions:
    Collection Operations

    • Field Collection

    • Headquarters Collection

    • Planning and Performance Analysis

    • Specialty Insolvency

    • Specialty Offers, Liens and Advisory


    Operations Support

    • Finance Research and Strategy

    • SB/SE Human Capital

    • Servicewide Operations

    • Technology Solutions

  3. This IRM 5.1.25, IDRS and Data Security for Collection, further defines requirements found in IRM 10.8.1, Information Technology (IT) Security, Policy and Guidance and IRM 10.8.34, Information Technology (IT) Security, IDRS Security Controls.

  4. If there is a conflict with or variance from this IRM andIRM 10.8.1, Information Technology (IT) Security, Policy and Guidance and IRM 10.8.34, Information Technology (IT) Security, IDRS Security Controls in regards to IDRS security, IRM 10.8.1 and IRM 10.8.34 have precedence unless specifically noted otherwise in IRM 10.8.1 or IRM 10.8.34, and/or unless requirements within this IRM are more stringent.

Roles and Responsibilities

  1. This section provides supplemental roles and responsibilities for personnel who have IDRS security-related responsibilities. These roles are further defined in IRM 10.8.34.3, Roles and Responsibilities.

  2. The IRM 10.8.34.3.1.3, Information Technology (IT) Security IDRS Security Controls, states the managers of IDRS users are responsible for day-to-day implementation and administration of IDRS security in their group. However, to relieve administrative burden on front line managers, SB/SE Collection Operations and Operations Support established dedicated Unit Security Representatives (USRs), known by their organizational title as Data Security Analysts (DSAs).

  3. The IDRS Data Security Group is assigned to the Collection Information Technology & Security (CITS) function. DSAs in Collection must perform security duties, which in other functions fall to managers of IDRS users. For purposes of consistency, this IRM uses the term DSA in lieu of USR. See IRM 1.1.16.2.3Collection Information Technology & Security, for information on the role and mission of the CITS function.

Managers of IDRS Users

  1. SB/SE Collection Operations and Operations Support Managers must:

    1. Coordinate with the DSA to ensure IDRS security is effectively implemented for the unit/group.

    2. Advise the DSA when a user is transferred in or out of the workgroup.

    3. Arrange periodic IDRS and Data Security awareness presentations for the workgroup. You may also contact your Service DSA for a group presentation.

    4. Ensure the DSA is notified immediately when an IDRS user no longer requires system access.

    5. Respond within five business days to the DSA with findings related to questionable accesses and/or other security report inquiries.

  2. SB/SE Collection Operations and Operations Support Managers may:

    1. Request secondary permissions in IDRS Online Reports Services (IORS) to view, add comments, and/or print their own unit reports.

    2. Be designated as an Alternate USR or Terminal Security Administrator.

    3. Designate a bargaining unit employee (e.g. Lead) to be an Alternate USR. However, a bargaining unit Alternate USR shall not review another employee’s IDRS actions.

    Note:

    This designation does not impact the roles and responsibilities of the DSA.

Annual Assurance Review Process - Federal Managers Financial Integrity Act (FMFIA)

  1. The Annual Assurance Review process requires managers to certify their IDRS security-related actions. IRM 10.8.34, Information Technology (IT) Security, IDRS Security Controls, provides authority to delegate IDRS security actions to the IDRS and Data Security Group. Therefore, with the exception of the IDRS Data Security Group Manager, Collection Operations and Operations Support Managers should respond as Non-applicable to all questions related to:

    1. Oversight of IDRS user profiles and profile restrictions.

    2. Oversight of USR profiles, USR training and USR security designations.

    3. Review and certification of IORS reports, including target certification rates.

    4. Oversight of contract personnel with IDRS accounts.

  2. Collection Operations and Operations Support Managers must continue to perform and certify the following actions during the Annual Assurance Review process:

    1. Ensure user profiles are locked when the employee must not require IDRS for more than 15 calendar days.

    2. Encourage employees to use command code LOKME and the Password Management Capability as appropriate.

    3. Ensure IDRS users complete required training.

Data Security Analyst (DSA)

  1. The DSA:

    1. Is the IORS Primary Reviewer and the Primary USR and must be reflected as such on the IDRS Unit and USR Database (IUUD) for all Collection Operations and Operations Support IDRS units.

    2. Is assigned a range of IDRS unit numbers aligned with the SB/SE Collection Operations and Operations Support areas.

    3. Shall maintain an active IDRS profile on both the Enterprise Computing Center - Martinsburg (ECC-MTB) and Enterprise Computing Center - Memphis (ECC-MEM) to ensure unrestricted backup support.

    4. Shall be profiled with ALLOW permissions to support users on all SB/SE home campuses.

    5. Is responsible for the review and certification of IORS and Security Audit and Analysis System (SAAS) reports.

  2. The DSA must also perform the following unit and account administration related tasks:

    1. Support the program goals of IT Cybersecurity by providing assistance, analysis and recommendations for action to SB/SE Collection Operations and Operations Support management.

    2. Process requests to add and/or delete IDRS command codes for unit and/or individual user profiles.

    3. Request new IDRS command codes using Form 9937, IDRS Unit Request, in IORS on behalf of the manager.

    4. Respond to user requests to unlock IDRS profiles and terminals.

    5. Support related functions, such as the IDRS Password Management Capability and the Integrated Automation Technologies (IAT) Toolbar.

    6. Maintain a centralized storage of Form 11377 and Form 11377-E, Taxpayer Data Access, for each SB/SE Collection Operations and Operations Support area.

    7. Use IORS to monitor IDRS usage and security.

    8. Use Security Audit and Analysis System (SAAS) to monitor accesses to the Transcript Delivery System (TDS), Modernized e-File Return Request and Display (MeF-RRD), and Remittance Transaction Research (RTR).

    9. Approve Online 5081 (OL5081) requests to add, delete or modify IDRS user profiles.

    10. Coordinate with other CITS functions to support reorganizations through the SB/SE Request for Organizational Change process.

    11. Submit updates to the IUUD to reflect current managerial contact information.

Alternate Data Security Analyst (DSA)

  1. At management's discretion, a cadre of alternate DSAs must perform the functions of the primary DSA as a collateral duty. Additionally, they:

    1. Are non-bargaining unit employees.

    2. Maintain active profiles on the ECC-MTB and ECC-MEM.

    3. Are profiled with ALLOW permissions to support users on all SB/SE home campuses.

Terminal Security Administrator (TSA)

  1. A Terminal Security Administrator (TSA) is designated by area management to provide additional IDRS user support in unlocking IDRS user profiles and terminals only. They may be bargaining or non-bargaining employees.

SB/SE Collection IDRS Data Security Manager

  1. The SB/SE Collection IDRS Data Security Manager must:

    1. Monitor and review IORS reports and SAAS work products to ensure security reports are thoroughly reviewed and timely certified.

    2. Collaborate with SB/SE Collection Operations and Operations Support and IT Cybersecurity personnel to address emerging security issues.

IDRS User Support

  1. IDRS users or their managers are encouraged to submit all requests to a centralized mailbox at *SBSE CITS IDRS. The mailbox is generally staffed from 6:00 a.m. to 6:00 p.m. (Central) Monday through Friday.

  2. Routine requests submitted by e-mail are generally completed within thirty minutes of receipt, except where final approval is required by the Campus IDRS Security Analyst.

  3. Upon receipt of an e-mail request from an IDRS user or manager, the DSA is responsible for providing IDRS user support as follows:

    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    Exception:

    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    ≡ ≡
    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    ≡ ≡
  4. The actions requested below require the IDRS user or manager to submit an OL5081.

    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
    1. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    ≡ ≡ ≡ ≡ ≡ ≡
    1. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    2. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    Note:

    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
    • ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

IDRS Unit Profiles

  1. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

  2. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

  3. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

  4. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    1. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    2. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

IDRS Command Codes

  1. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

  2. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

  3. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

Requests for Common Command Codes
  1. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

  2. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

Requests for Uncommon Command Codes
  1. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    1. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    2. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    3. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

      ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
      ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
      ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
      1. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

      2. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

      3. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

      4. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

      ≡ ≡
  2. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

  3. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

IDRS Online Reports Services (IORS)

  1. The IDRS Online Reports Services (IORS) is a web based application that makes IDRS security reports available online to IDRS security staffs and authorized business reviewers.

  2. The DSA is designated as the IORS Primary Reviewer for all Collection Operations and Operations Support IDRS units.

  3. Managers of IDRS users may be granted secondary permissions in IORS to view, add comments, and print IORS reports for their assigned unit.

Types of IORS Reports

  1. There are four weekly security reports available to authorized users for review and necessary actions.

    • Employee Count by Site/Unit

    • Master Register of Active IDRS Users

    • Security Violations

    • Sensitive Access (Other/Spouse)

  2. There are three monthly reports available to authorized users for review and necessary actions.

    • Automated IDRS Sign-Offs Due to User Inactivity

    • Monthly IDRS Security Profile Report

    • Password Management Activations

Weekly Security Reports - Review and Action (No Certification Required)
  1. The Employee Count by Site/Unit report lists the number of active users in each unit. The DSA must review this report and take action as warranted, such as deleting empty units that are no longer required to support the area footprint.

  2. The Master Register of Active IDRS Users report lists numerous fields of information for all active users in the unit. The DSA must incorporate the Master Register of Active IDRS Users report in their monthly security review activities.

Monthly Security Reports - Review and Action (No Certification Required)
  1. The Automated IDRS Sign-Offs Due to User Inactivity report lists those users whose IDRS sessions terminated after 120 minutes of inactivity. The DSA must take the following actions:

    • Identify IDRS users with more than 15 automatic sign-offs in a month.

    • Advise those users to sign-off IDRS when not in use to prevent an unauthorized access.

    • Instruct users how to periodically refresh their IDRS session if IDRS is required on a continuous basis.

    Note:

    While this report is not certified independently, it is incorporated as an aspect of certifying the Monthly IDRS Security Profile Report.

  2. The Password Management Activations report lists the number of users in each unit who have activated this capability. Where a unit fails to reflect a 100% activation rate, the DSA must research IDRS to determine if Password Management has been activated since the report was generated.

    • If it has, no further action is warranted.

    • If it has not, the DSA must send an e-mail to the user with a copy to the group manager requesting the user to activate the Password Management Capability. The DSA must attach the instructions to assist the user with activation.

Security Reports Requiring Certification
  1. The DSA is required to review and certify the following security reports:

    • Weekly Security Violations Report

    • Weekly Sensitive Access (Other/Spouse)

    • Monthly IDRS Security Profile Report

Weekly Security Violations Report
  1. This report lists all security violations recorded by IDRS users, such as:

    • Password Mismatch

    • Name Mismatch

    • SINON Error (PWMGT)

    • Response Error (PWMGT)

    • Command Code Not in Profile

    • Locked Profile

  2. This report must be certified within 14 calendar days to be considered timely.

  3. The DSA is required to complete the research and take appropriate actions as follows:

    1. The report reflects a user with SINON violations.

      If ... Then ...
      The research shows a user has four or more violations with any combination of:
      • Password Mismatch

      • Name Mismatch

      • SINON Error (PWMGT)

      • Response Error (PWMGT)

      (1) Send an e-mail to the user, with a courtesy copy (cc:) to the manager to confirm the following:
      • The user committed these errors

      • The violations were not the result of an unauthorized attempt to access IDRS

      (2) Advise Treasury Inspector General for Tax Administration (TIGTA) of the user's response if the user does not agree they committed the violations.
    2. The report reflects a user with four or more Command Code Not in Profile violations. Research the user's profile to determine if the command code(s) were previously added.

      If ... Then ...
      Command Codes(s) were previously added No further action is required
      Command Code(s) were not previously added (1) Determine if the command code(s) is authorized for SB/SE Collection Operations and Operations Support function and position use (Refer to IRM 5.1.25.3.2, IDRS Command Codes).
      (2) If authorized, e-mail the user with a cc: to the manager stating:
      • The command code(s) accessed resulting in a security violation

      • If the command code is needed for their position, to obtain managerial approval to have the command code added to their profile.

        Note:

        If not needed or it was an input error, no further action is required.


      (3) If not authorized, e-mail the user, with a courtesy copy (cc:) to the manager, advising the command code is restricted and/or not allowed in SB/SE Collection Operations and Operations Support profiles.
    3. The report shows a user with a Locked Profile violation. Research the user's profile to determine the current status.

      Example:

      System Lock due to inactivity, Security Lock, or the employee initiated a Self-Lock.

      If ... Then ...
      The IDRS profile is unlocked No further action is required.
      A System Inactivity Lock exists Contact the manager to determine if account should be unlocked or remain locked.
      A Security Lock exists Contact the manager to request the current status of the user.
      A Self-Lock was initiated Review the dates the Self Lock was set and date the violation occurred. On a case-by-case basis, the DSA may contact the Manager to determine if the employee is out of the office for the period in question.
  4. The DSA must document IORS for every actionable event.

  5. In the comments area, the DSA must document all research, contacts made with the user or manager, and their conclusion.

  6. For each individual action taken, the DSA must select the appropriate action for the event from the drop down menu:

    • Review Completed - No Follow-up Needed

    • Review Completed - Follow-up Performed

    • Follow-up Action Required

    • Other (Comment Required)

  7. The DSA must address Report Level Actions, Report Level Comments and Current Certification Status, which apply to all displayed units.

    Report Level Items Actions
    Report Level Actions
    • Reviewed and Validated - No Follow-up Action Needed

    • Follow-up Action Needed

    • Follow-up Action Completed

    • Referred to AWSS or TIGTA

    • Other (Comment Required)

    Report Level Comments
    • The DSA must summarize actions taken to review the Weekly report.

    Current Certification Status
    • Report Certified

    • Remove Certification / Not Certifying

Weekly Sensitive Access (Other/Spouse)
  1. This report lists users who have attempted to or accessed other employees’ or the spouses/ex-spouse of other employees’ accounts.

  2. The DSA is required to review each unique Social Security Number (SSN) to ensure all accesses to other Internal Revenue Service (IRS) employees' and/or their spouses' accounts are business-related.

  3. Each access must be supported by one of the following indicators:

    Note:

    Justification may have been recorded on a prior IORS report

    1. Direct case assignment in SB/SE Collection inventory applications, such as the Integrated Collection System (ICS), Automated Insolvency System (AIS-4), Automated Lien System (ALS) or Automated Offers in Compromise (AOIC)

    2. Related case assignment on SB/SE Collection inventory applications

    3. Evidence of cross compliance checks

    4. Department of Justice or other official requests

    5. Confirmed input error supported by the identification of another assigned case with similar Taxpayer Identification Number (TIN), such as a transposition or formatting error

  4. The DSA is required to certify all accesses through collection case assignment by querying the SSN on SB/SE Collection inventory applications. When the accessing user is assigned the case or is another member of the same group the DSA must certify the access.

    Note:

    The DSA must leave a history on ICS identifying the purpose of the access.

  5. This report must be certified within 14 calendar days to be considered timely.

  6. The DSA must take the actions shown in the following table if unable to certify the access.

    If ... Then ...
    No record is located on the inventory applications Research Form 11377 or Form 11377-E retention files.
    A document exists with sufficient explanation Certify the access.
    No document exists Research IDRS and/or other applications, such as Accounts Management Services (AMS) to locate a cross-reference TIN.
    A cross-reference TIN is located Research inventory applications to determine whether the related TIN controls case assignment.

    Note:

    The DSA must prepare Form 11377 or Form 11377-E for all IDRS accesses of employee/spouse accounts. Submit both copies of the form to the SB/SE Collection IDRS Data Security Manager.

  7. If the research performed above does not confirm or certify the access the DSA must e-mail the manager of the accessing user to validate the access. The DSA must request a response within five business days and include in the e-mail:

    • Specific information to identify the user

    • The date and time stamp of the access

    • The account accessed

    • The command codes accessed

    • The DSA's research

    Based on the e-mail response, the DSA must take the actions in the following table:

    If ... Then ...
    The manager provides a valid reason for the access The DSA must conduct additional research to confirm a related case assignment.

    Example:

    If the response states the access is a cross compliance check to a business entity or a transposition error, the DSA must independently confirm the actual case assignment.

    Exception:

    Centralized Campus Operations receive recorded phone calls, which may be reviewed locally, for up to 30 days after the contact.

    The manager cannot provide a valid reason for the access The DSA must initiate Form 9936, Request for Audit Trail Extract, to view what actions were recorded before and after the access in question.

    Note:

    If a manager requires an IDRS audit trail for any reason not associated with a security report, they may request it through the DSA or by direct contact with IT Cybersecurity.

    The manager has not replied within five business days The DSA must send a copy of the initial e-mail to the territory manager with a cc: to the manager.
    The DSA does not receive a response within an additional five business days The DSA must notify the SB/SE Collection IDRS Data Security Manager.
    The DSA cannot certify an access through independent research, managerial response and/or reviewing audit trails The DSA must submit a referral to TIGTA for follow up in accordance with IRM 10.8.34.6.3.1.2.3.
  8. In the comments area on IORS, the DSA must clearly and concisely document all research conducted and actions taken in sufficient detail, including research results and any contacts with or information provided by the user or the manager. Comments must provide sufficient detail to enable any reviewer to determine how the DSA certified the access or why the DSA referred the access to TIGTA.

    Note:

    If a TIGTA referral is required, the DSA must record the Complaint Number as the final entry prior to certifying the report.

  9. For each individual action taken, the DSA must select the appropriate action for the event from the drop-down menu:

    • Review Completed - No Follow-up Needed

    • Review Completed - Follow-up Performed

    • Follow-up Action Required

    • Other (Comment Required)

  10. The DSA must address all Report Level Items, Report Level Comments and Current Certification Status, which apply to all displayed units as shown in IRM 5.1.25.4.1.3.1(7).

Monthly IDRS Security Profile Report

  1. The Monthly Security Profile Report provides a summary of various IDRS security aspects. Every unit must be reviewed for the following categories:

    • Locked Profiles

    • Automated Command Code Access Control

    • Sensitive Command Code Combinations

    • Security Command Code Usage

    • Master Register of Active IDRS Users

    • Command Code Activity

  2. This report must be certified within 28 calendar days to be considered timely.

Locked Profiles

  1. The DSA must review locked IDRS profiles of 28 days or more due to inactivity.

    Research IDRS to determine if the user has been deleted from IDRS or if the profile is still locked.

    1. If the user profile has since been unlocked or deleted, no further action is required.

    2. If the user profile is still locked, the DSA must send an e-mail to the manager to determine if the user still requires IDRS access.

  2. Based on the manager's response, the DSA must perform the following actions:

    1. If the manager confirms the user requires IDRS access, the user must be unlocked upon request.

    2. If the manager determines the user no longer requires IDRS access, the DSA must delete the user from IDRS. OL5081 must update overnight, removing IDRS as an active application.

Automated Command Code Access Control

  1. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

  2. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    1. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    2. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    3. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    4. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

  3. ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

    Exception:

    ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡

Sensitive Command Code Combinations

  1. SB/SE Collection Operations and Operations Support IDRS units may contain sensitive command code combinations, which require increased oversight. See IRM Exhibit 10.8.34-6, Sensitive Command Code Combinations, for the list of codes.

  2. The DSA must ensure the UCCP does not contain any sensitive command code combinations.

  3. The DSA must monitor use of Sensitive Command Code Combinations by position title and contact the user's manager for confirmation as needed.

Security Command Code Usage

  1. The DSA must query their units to identify the use of security command codes to ensure they are apprised of all users approved by local management to function as Alternate USRs or TSAs.

  2. If security command codes have not been used for over six months, contact the user's manager to confirm the user's security role. Based on the manager's response, perform the following actions:

    1. If the manager concurs with the user's continued security role, no further action is required.

    2. If the manager determines the user no longer requires security command codes, direct the manager to initiate an OL5081 Modify User Profile request to delete the user's security command codes.

    Exception:

    The Centralized Campus Operations may be exempt as each Manager and/or Lead typically has access to their own unit and/or may be second shift when no other coverage is available.

Master Register of Active IDRS Users

  1. The Master Register lists active IDRS users in the unit.

  2. The DSA must forward the Master Register to the manager to determine if any corrective action is necessary.

  3. The DSA is responsible for taking any corrective actions necessary, such as: moving the user to another unit, updating the user’s phone number in IDRS and confirming approved pseudonym names are reflected in IDRS.

Command Code Activity

  1. The DSA must review Unit and Individual command code usage to determine:

    1. If the MPAF command codes are appropriate for the work performed by the users in the unit.

    2. Whether UCCP command codes are used by at least 90 percent of IDRS users in the unit. The UCCP must not contain any sensitive command codes unless 100 percent of the employees in the unit need the command code to do their work.

  2. The DSA must review the profile of each IDRS user to identify any unauthorized command codes. See Exhibit 5.1.25-2 for a list of command MPAF production command codes approved for use by SB/SE Collection Operations and Operations Support.

  3. Based on results of the Unit and Individual command code review, take the following action, if appropriate:

    1. Request the IDRS Security Account Administrator modify or delete the command codes that are not authorized, used or no longer needed in the MPAF or UCCP.

    2. Review users with command code REPTS in their profile, especially users in IORS specific units, to determine if IORS access is still needed.

      Exception:

      The Centralized Campus Operations may be exempt as each Manager typically has access to their own unit and are required to periodically access and review their own report.

    3. Report questionable patterns of command code activities to the group manager.

IORS Documentation

  1. The DSA must only enter comments at the Report Level Items, as the Monthly Security Profile Report is certified in its entirety.

  2. The DSA must summarize actions taken to address each security aspect. The monthly review may include the entire area or a specific unit range.

  3. The DSA must address all Report Level Items, Report Level Comments and Current Certification Status which apply to all displayed units as shown in IRM 5.1.25.4.1.3.1(7).

Security Audit and Analysis System (SAAS)

  1. Audit trails for modernized applications are stored in the SAAS.

  2. In compliance with each application's audit plan, business units are responsible for reviewing SAAS audit trails and certifying accesses to taxpayer data.

  3. The IDRS Data Security Group currently monitors the audit trail extracts for access to TDS, MeF-RRD and RTR. Security reviews in SAAS may be expanded at any time to include additional applications.

  4. For each application there is a General Access and Access to Employee report. The General Access report is subject to a sample review and certification. The business unit determines the sample percentage, which is subject to change. The Access to Employee report is subject to 100% review and certification.

  5. The DSA must generally certify sample reports within 14 calendar days of receipt. Management may approve longer certification dates, as appropriate.

  6. The DSA must follow the established certification procedures by attempting to confirm case/related case assignment in SB/SE Collection Operations and Operations Support inventory applications. If case assignment is not independently confirmed, the DSA must contact the group manager to justify the access.

  7. If the DSA is unable to certify an access through independent research or managerial response, the DSA must submit a referral to TIGTA for follow-up in accordance with IRM 10.8.34.6.3.1.2.3.

  8. Unlike IORS, SAAS does not have the capability to capture review comments. The review notes documented by the DSA are maintained by the SB/SE Collection IDRS Data Security Manager for 90 days. Certification results are submitted to IT Cybersecurity as directed.

Form 11377/11377-E, Taxpayer Data Access

  1. The purpose of Form 11377 or Form 11377-E, Taxpayer Data Access, is to provide employees with a method to document accesses to taxpayer return information, when the accesses:

    1. Are not supported by direct case assignments

    2. Are performed in error

    3. May raise suspicion

  2. Use of Form 11377 or Form 11377-E is voluntary.

  3. If the employee completes the Form 11377 or Form 11377-E , the manager must forward the IRS copy to the designated head of office designee by close of business or as soon as possible. In SB/SE Collection Operations and Operations Support, the head of office designee is the assigned area DSA.

  4. Copies of Form 11377 or Form 11377-E containing taxpayer data, may not be retained by the employee, the manager, or in any location other than with the IDRS Data Security Staff.

  5. The DSA maintains Form 11377 or Form 11377-E for six years in access date order. There is no segregation by function, group, or accessing employee's name.

  6. The DSA must respond promptly to requests from Labor Relations or TIGTA and provide copies of any Form 11377 or Form 11377-E needed for an ongoing UNAX investigation.

Acronyms

Following is a list of acronyms used throughout this IRM.

Acronym Definition
AIS-4 Automated Insolvency System
ALS Automated Lien System
AMS Accounts Management Services
AOIC Automated Offers In Compromise
CFOL Corporate Files On-Line
CITS Collection Information Technology & Security
DSA Data Security Analyst
ECC-MEM Enterprise Computing Center - Memphis
ECC-MTB Enterprise Computing Center - Martinsburg
FMFIA Federal Managers Financial Integrity Act
IAT Integrated Automation Technologies
ICS Integrated Collection System
IDRS Integrated Data Retrieval System
IORS IDRS Online Reports Services
IT Information Technology
IUUD IDRS Unit and USR Database
Mef-RRD Modernized e-File Return Request and Display
MPAF Maximum Profile Authorization File
OL5081 Online 5081
PAR Personnel Action Request
RTR Remittance Transaction Research
SAAS Security Audit and Analysis System
SSN Social Security Number
TIGTA Treasury Inspector General for Tax Administration
TDS Transcript Delivery System
TIN Taxpayer Identification Number
TSA Terminal Security Administrator
TSID Terminal Security Identification
UCCP Unit Command Code Profile
UNAX Unauthorized Access
USR Unit Security Representative

Common Command Codes - SB/SE Collection Operations and Operations Support

The following tables list the common command codes approved for use by SB/SE Collection Operations and Operations Support employees.

Note:

Some command codes are marked as Sensitive in the IDRS Command Code Table or have a Sensitive Connotation and may only be placed in the Limited MPAF.

≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡
≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡
≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡


≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡ ≡
≡ ≡ ≡ ≡ ≡ ≡ ≡