IRS disclosure awareness training videos are available for local, state and federal governmental agencies that receive federal tax information (FTI). The videos help agencies with their annual requirement to certify that their employees understand the security policies and procedures.
The IRS Office of Safeguards created three agency specific videos to help explain several key concepts in protecting the confidentiality of FTI. Topics discussed include the eight key tenets of safeguarding FTI, the importance of Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies PDF, Safeguards webpage, submission of information to Safeguards and the penalties for unauthorized browsing and disclosure of FTI.
General session for all agency types
Safeguards security awareness training
The Office of Safeguards is working to update this resource, please refer to the information below until the video/podcast can be restored.
Associate Director: Hello. I am Associate Director from the IRS Office of Safeguards.
Welcome to Safeguards Disclosure Awareness Training.
The purpose of this video is to provide training for federal, state, and local agency employees, agents, and contractors.
The Office of Safeguards verifies compliance with 6103(p)(4) safeguard requirements.
It does this through the identification and mitigation of any risk of loss, breach, or misuse of federal tax information by over 300 external government agencies.
Each year, billions of pieces of FTI are disclosed, as the law allows.
The laws that permit disclosure also require its protection.
We partner with each agency to protect federal tax information.
Our agency partners play a vital role in safeguarding FTI by building effective security controls into your processes, procedures, and systems.
You are responsible for ensuring the information is protected appropriately from the time you receive it until the time it´s destroyed.
The American public expects two things from both of us.
First, that we work together proactively to be as effective as possible, and second, that we safeguard their personal data.
A good security awareness program is, by far, the most effective and the least expensive part of the overall security program.
For many of you, this is simply a refresher on disclosure awareness, while for others, this may be the first time you have been exposed to the concepts.
Before we move into the substance of the discussion, I would like to thank you for everything you do to protect the confidentiality of federal tax information.
I truly appreciate it.
Manager: Hello. I am a Safeguards Manager (Manager), and I´ll be the moderator for this discussion.
I have extensive experience with the IRS and have worked in many capacities within the Safeguards office.
Joining me as the panel are the Chief of Safeguard Review Team (Review Chief), Information Technology Specialist (IT Specialist), and the Program Analyst (Analyst).
The Review Chief, Analyst, and IT Specialist have all served as disclosure enforcement specialists in the safeguards operation before moving into their current positions.
We have all conducted on-site reviews.
We´re grateful for the opportunity to visit with you today.
We´ll be discussing several key concepts that are used in protecting federal tax information, or FTI.
It´s up to us to protect this sensitive information while creating and cultivating confidence in our agencies.
So let´s get started.
We will begin our discussion today with a question we´re often asked.
IT Specialist, what do we mean by federal tax information, or FTI?
IT Specialist: Manager, that´s a very good question.
FTI consists of two things.
One, a tax return, and two, return information.
FTI can be either or both.
FTI is any return or return information received from the IRS or a secondary source such as Social Security Administration, Federal Office of Child Support Enforcement, Bureau of the Fiscal Services, or the Centers for Medicare and Medicaid Services.
FTI is also shared under agreements allowed by the statute or regulations.
Analyst: A tax return includes all amendments, supplements, supporting schedules, attachments, or lists filed on paper or electronically along with the return, such as Forms 1040, 941, 1120, and other informational forms, such as a Form 1099 or a W-2.
Manager: So, now we know what is considered FTI for the return.
What is return information?
Analyst: I´d like to answer that, Manager.
Return information, in general, is any information collected or generated by the IRS regarding any person´s liability or possible liability.
The Internal Revenue Code defines return information very broadly.
It includes, but is not limited to, the return itself, as well as any information that the IRS obtained or developed that relates to the potential tax liability.
It could be from anywhere.
Review Chief: FTI includes the information extracted from a return, including names of dependents, the location of a business, the taxpayer´s name, address, and identification number.
Even if identifiers such as name, address, and identification number are deleted from this information, it is still considered FTI.
IT Specialist: We need to emphasize that the definition of return information includes anything relating to a tax account.
Return information includes the status of whether return was filed, if it´s being processed, if it is under examination, if it´s subject to other investigation, or in collection status.
It also includes information contained on transcripts of the taxpayer´s account.
This information is all FTI.
Manager: What about the copies of tax returns that clients or their representatives have given to the agency to verify their data?
Are those returns considered FTI?
Review Chief: No, Manager. Returns from clients are not federal tax information.
Source is the key to knowing whether or not the data is FTI.
The information must be derived from the IRS or a secondary source, as previously mentioned, for it to be considered federal tax information.
This is what you need to remember.
If the source is your agency´s client or a client´s representative, it is not FTI.
If the source is the IRS or an IRS secondary source, the information is FTI.
Manager: IT Specialist, what happens when the information from the return is transferred to a different format, document, or computer application?
IT Specialist: Agency personnel often forget that any information derived from the FTI is considered federal tax information and must be safeguarded.
Derived FTI includes things like photocopies, scanned data, or information transcribed into a form, letter, application, or spreadsheet.
It could be something as basic as a sticky note where information from FTI was jotted down for quick reference.
The information on the sticky note then becomes FTI, which requires safeguarding.
Review Chief: When there is any doubt, ask yourself, where did the data originate?
If the answer is IRS or one of the secondary sources, it is FTI and must be safeguarded.
Manager: Analyst, what requires FTI to be kept confidential?
Analyst: Title 26 of the United States Code or Internal Revenue Code, section 6103, gives the IRS the authority to disclose FTI to federal, state, and local agencies.
It also dictates that the disclosed FTI must be held confidential.
IRS shares billions of tax records each year to increase compliance, enforcement, and service to taxpayers.
These records help agencies generate hundreds of millions of dollars in revenue and provide verification for those requesting assistance.
With all this information sharing comes great responsibility to protect it.
Manager: Analyst, disclosure is a running theme in law.
Please explain what the term "disclosure" means.
Analyst: The Internal Revenue Code defines disclosure as making known of return or return information to any person in any manner.
We must be mindful that when congress gave IRS the authority to disclose FTI, it also provided IRS statutory provisions to protect the private information of U.S. citizens.
The provisions provide the foundation for safeguarding FTI, which is where agency personnel and the Office of Safeguards entered the picture.
Review Chief: The law only allows FTI to be disclosed to those who are authorized and who have a need to know.
Manager: Thank you, Review Chief.
IT Specialist, can you please tell us about Publication 1075 and why it´s important to the agencies who receive federal tax information?
IT Specialist: Publication 1075, Tax Information Security Guidelines for Federal, State, and Local Agencies, details the security requirements for all agencies that receive, process, store, or transmit FTI.
The Publication 1075, for all intents and purposes, is the guiding document for the Office of Safeguards and our agency partners.
It provides the information needed to meet the strict requirements for requesting, receiving, safeguarding, and destroying FTI.
Analyst: The requirements within the publication originate from several different sources.
Internal Revenue Code, or IRC, Section 6103, IRS policy and procedures, and the National Institute of Standards and Technology Special Publication 800-53.
These requirements are designed for moderate-risk systems and are the backbone of information technology confidentiality requirements.
Review Chief: Each agency that receives federal tax information must become familiar with Publication 1075 and its requirements.
It outlines all the policies and procedures for safeguarding FTI within your agency.
Publication 1075 is periodically updated and published electronically.
The latest version is always available in the Safeguard section of the IRS´ website at IRS.gov.
Manager: Wow. That´s really helpful information.
IT Specialist, could you please tell us more about the Safeguard section of the IRS website?
IT Specialist: Certainly.
You can find comprehensive information by going to IRS.gov and searching for the "Safeguards Program" page.
Type the words "Safeguards Program" into the search box.
We update the website often, so I encourage you to visit the page frequently for most current information.
Our website has a lot of useful features and information you´ll need.
It includes alerts, technical information, and computer security requirements, which are documented in safeguards computer security evaluation matrices.
Review Chief: You´ll find recommendations on how to comply with Publication 1075 requirements, templates for internal inspections, and guidance on how to complete the forms.
Instructions for reporting unauthorized accesses, disclosures, or data breaches are on our site.
And a link to this video is on the webpage in case you need to revisit it or share it with new staff members.
Manager: That´s great information.
It sounds like that Safeguards website´s a one-stop shop for all of the safeguarding information.
Now we´re going to examine the key tenets of safeguarding.
The eight areas of focus are as follows -- recordkeeping, secure storage, restricting access, employee awareness and internal inspections, reporting, disposal, need and use, and computer security.
Let´s begin with recordkeeping.
Analyst, can you please tell us a little bit about recordkeeping?
Analyst: Recordkeeping requires that each agency maintain a system of standardized records or logs for all FTI.
Records and logs come into play at the time that the FTI is received, and they must remain active until the FTI is destroyed.
The logs may be in paper format, or they may be electronic.
The recommended data elements for the logs and their retention schedule are listed in Publication 1075.
An agency must be able to show the movement of FTI on their logs as it flows through the process.
If you provide FTI to the next person in the process, you must log where it went.
And the next recipient, or the new recipient, must log that they received it.
Review Chief: Whether the FTI is on a computer system or on a piece of paper, it must be tracked on a log from receipt to disposal.
Manager: Thanks, Review Chief.
Secure storage is the second of the key tenets.
What are the requirements for secure storage of FTI?
Review Chief: Secure storage is based on the concept of minimum protection standards, or the two-barrier rule.
Basically, there must always be two barriers between someone who is not authorized to see the FTI and the information itself.
IT Specialist: Let´s talk a minute about storage of FTI.
Tangible items such as a piece of paper, folder, or CD are usually locked in a filing cabinet or secured in a locked office.
So, the locked filing cabinet and the locked office constitute your two barriers.
But during business hours, the FTI may need to be outside of the locked cabinet.
So, in this instance, an employee who is present at all times while the FTI is in use can serve as the second barrier.
This person should have their badge above their waist, indicating they are agency personnel.
Review Chief: The two-barrier rule applies to all agency locations.
It could be the headquarters office or an alternate work site if personnel are allowed to work at home or elsewhere outside the office setting, certainly, the computer facilities where mainframes, servers, routers, and switches are located, as well as off-site storage, where backup tapes are kept, and field offices.
Federal tax information housed in any location within an agency must have two barriers protecting it at all times.
IT Specialist: One of the things we commonly see when we do on-site reviews is a situation where an agency is looking at the two barriers from the outside in, beginning at the guards.
The two-barrier rule starts with the FTI and proceeds from the inside out.
In other words, start at the FTI and look for what prevents it from being accessed by someone who is not authorized.
It´s likely that you´ll never identify the guards as one of your two barriers.
Remember, people enter your agency every day, going past the guards.
However, they are not allowed in the area where the FTI resides.
Look for the two barriers from the inside out.
Manager: Thanks, IT Specialist.
Again, that´s helpful information.
The two-barrier rule is a very common question that we get when it comes to FTI and safeguarding FTI.
Why is limiting access, however, such a key part of an effective security program?
Analyst: Restricting access is based on the premise that only agency employees, agents, and contractors who have a need to know are allowed access to FTI.
Basically, need to know is based on position.
If you need federal tax information to complete your job, then you have a need to know.
Restricting access to the greatest extent possibly makes FTI less vulnerable.
IT Specialist: You can restrict access by locking paper in a file cabinet, by requiring key or card access to rooms where FTI is stored, and through a secure log-in and password process on the computer systems.
When mailing FTI, double package it to prevent exposure if the outer packaging is damaged.
Always be mindful of the need-to-know aspect, and grant access within your agency to only those who have that need.
Review Chief: In some agencies, contractors are not allowed access to FTI by statute.
In these agencies, contractors may have access to any of your agency data, but it is the agency´s responsibility to ensure the contractors never have access to FTI.
For example, if a contractor comes in to repair a computer, the contractor will need to be escorted at all times, and security controls must be in place protecting the FTI.
Manager: An essential practice in restricting access is a notification requirement to alert others that data is, indeed, FTI and is restricted.
How are agencies expected to provide notification?
Analyst: I´ll be glad to explain that, Manager.
Labeling is an important component of restricting access to FTI, whether it´s stored electronically or on paper.
Labeling provides a warning that the data is restricted.
FTI must be clearly labeled as federal tax information and handled in such a manner that it is not misplaced or that it becomes available to unauthorized personnel.
Review Chief: Publication 1075 provides information on how to order labels for paper documents and backup tapes in the appropriate language needed for warning banners displayed on the screens of computers providing access to FTI.
It makes sense that labeling all FTI would deter unauthorized access.
Manager: We have been talking about the key tenets of safeguarding FTI for the last few minutes.
Obviously, it´s important for those of us who have access to data to understand each of these tenets.
How does an agency impart that knowledge?
IT Specialist: Agencies are required to provide awareness training for their employees to help them gain an understanding of the agency´s security policies and procedures for safeguarding FTI.
The training must be provided before access to FTI is granted and annually thereafter.
The requirements for the training are in Publication 1075.
Analyst: Each employee who completes the training must sign a form acknowledging their understanding of the requirements to protect FTI and the sanctions for unauthorized browsing or unauthorized disclosure.
Your agency must retain these acknowledgement certificates according to the retention schedule in Publication 1075.
Manager: After the training, how does an agency verify those individuals are following the security policies and procedures for protecting FTI?
Review Chief: Agencies must conduct internal inspections which should be similar to our safeguards on-site reviews.
These inspections provide your agency with a way to identify its compliance with Publication 1075 requirements.
Inspections must be conducted at all locations where FTI resides.
IT Specialist: The time frames for conducting these inspections are listed in Publication 1075.
Templates are available on Safeguards´ webpage of IRS.gov.
These templates must be notated and included in the agency´s annual Safeguards Security Report.
Manager: Wow, another acknowledgement of the Safeguards’ website.
How does an agency report its safeguarding efforts to us?
Analyst: Each agency must submit an annual Safeguards Security Report (SSR).
The SSR describes the procedures established and used for safeguarding.
The SSR is certified by the head of your agency, indicating the agency´s compliance with safeguarding requirements.
Review Chief: Then, every six months, each agency submits a corrective action plan, which provides a status update on any findings from the on-site review.
This documents the corrective actions completed and those planned.
The IRS Office of Safeguards tracks the status of all findings until they are closed.
IT Specialist: Advanced notification and approvals must be submitted 45 days before your agency secures contracting services or begins specific IT infrastructure changes.
As the IT environment changes, so do the requirements for notifications, so be sure and check our website and the current version of Publication 1075 to determine whether the activity your agency is considering requires a notification.
Analyst: We answer technical inquiries that your agency sends via e-mail regarding the processes and procedures for safeguarding FTI.
Review Chief: If you discover a possible improper inspection or disclosure of FTI, and this could include a breach or security incident of any kind, the individual making the observation or receiving information must contact the Office of Safeguards immediately.
The contact should be made as soon as possible but no later than 24 hours after the discovery.
Analyst: Your agency must notify the Office of Safeguards by e-mail.
Even if all information is not available about the incident, immediate notification is still the most important factor.
Review the latest version of Publication 1075 for details on how to report data incidents.
IT Specialist: All reports, notifications, technical inquiries, and data incidents must be sent encrypted to SafeguardReports@IRS.gov or through secure data transfer if your agency has the capability.
Current templates and submission procedures are available on our website.
Manager: We talked earlier about recordkeeping from receipt to destruction.
Are there requirements for destroying FTI?
Review Chief: Absolutely.
As important as it is to track the FTI received, it is equally important to know when and what FTI has been destroyed.
The agency must document the destruction in their annual SSR and provide a sample of the log used to record it.
Analyst: FTI may be disposed of by destroying or returning it to the IRS, as outlined in Publication 1075.
As FTI is increasingly maintained in electronic systems, destruction requirements are continually changing.
Check our website regularly for any alerts and changes to these requirements.
Review Chief: Regardless of how the agency is destroying the FTI, the method must make it unreadable or unusable.
Manager: Another consistent theme seems to be logging, whether electronic or physical.
Analyst, can agencies use the FTI for any agency purposes once they receive it?
Analyst: No, Manager. They cannot.
The Internal Revenue Code is very direct on how agencies can use it.
They are prohibited from using FTI for any purpose other than that authorized by statute.
Before the agency receives FTI, the IRS must approve its intended use.
Part of the Safeguards on-site review is to verify that the data is being used as approved.
Manager: Deficiencies in computer security account for 98% of the weaknesses identified during Safeguards´ on-site reviews.
Computer security methods are constantly changing.
IT Specialist, can you tell us a bit about computer security and how it applies to safeguarding FTI?
IT Specialist: The focus of the computer security portion of the on-site review is based on requirements outlined in the National Institute of Standards and Technology (NIST) Special Publication 800-53.
We review your agency´s IT security controls using evaluation matrices and automated testing tools.
We also examine written documentation and policies and procedures in your IT environment.
To be proactive with safeguarding, your agency can verify their IT systems receiving, processing, storing, or transmitting FTI are compliant with Publication 1075 requirements by using the Safeguards computer security evaluation matrices found on our website.
Review Chief: Logging and auditing are required to effectively capture all access, modification, deletion, and movement of FTI by each unique user.
This will identify any external breaches or suspicious activity.
IT Specialist: Automated testing is performed on various systems during an on-site review.
We use an industry-standard compliance and vulnerability assessment tool to evaluate the security of systems that store, process, transmit, or receive FTI.
This tool conducts configuration compliance checks using Center for Internet Security (CIS) benchmarks supplemented with IRS-specific requirements.
The audit files are available on our website.
Manager: Review Chief, are there any consequences for the misuse of FTI?
Review Chief: Yes. There are two criminal penalties associated with either or both unauthorized access or unauthorized disclosures of FTI.
This applies to individuals even after they´re no longer employed with your agency.
There is a lifelong prohibition from disclosing federal tax information.
The most severe penalty is for unauthorized disclosure, which means that you were providing FTI to someone that is not entitled to have it.
The penalty is five years of imprisonment, a $5,000 fine, or both, plus the cost of prosecution.
Analyst: The penalty for unauthorized access is one year imprisonment, $1,000 fine, or both, plus the cost of prosecution.
Unauthorized access is reviewing the data when you are not entitled to look at it.
You can actually be guilty of both offenses and prosecuted for both unauthorized disclosure and unauthorized access.
Let´s not forget that taxpayers who are harmed by unauthorized access or unauthorized disclosure may seek civil damages.
The taxpayer may receive a minimum of $1,000 for each unauthorized access or disclosure or actual damages, whichever is greater, plus punitive damages and the cost of the prosecution.
Review Chief: It is important to remember that you, not your agency, are liable for these penalties.
Manager: Wow, Review Chief. Those are pretty significant penalties.
I definitely wouldn´t want to run afoul of that.
I would like to thank the panel for their discussion on this important subject of protecting federal tax information.
Their answers have given us insight into safeguarding.
We encourage you to visit our website and review the current revision of Publication 1075.
Remember, when you are successful, we are successful.
I would like to turn this back to the Associate Director to close out.
Associate Director: We all have a shared responsibility to ensure that federal tax information is disclosed only to those with a need to know and only used as authorized by statute or regulation.
We at the IRS are confident in your diligence, that you adhere to good security protocols, that you are as vigilant as we are about protecting FTI and using it appropriately.
As our IRS Disclosure Awareness Training video concludes, I encourage you at all times to ensure that the data you hold is secure and protected.
Please remember to follow the security requirements within your agency.
Thank you for your time, but most of all, thank you for your efforts to protect the confidentiality of federal tax information.
General session and session for state and federal child enforcement agencies
The Office of Safeguards is working to update this resource, please refer to the information below until the video/podcast can be restored.
Associate Director: Hello. I am Associate Director from the IRS Office of Safeguards.
Welcome to Safeguards Disclosure Awareness Training.
The purpose of this video is to provide training for federal, state, and local agency employees, agents, and contractors.
The Office of Safeguards verifies compliance with 6103(p)(4) safeguard requirements.
It does this through the identification and mitigation of any risk of loss, breach, or misuse of federal tax information by over 300 external government agencies.
Each year, billions of pieces of federal tax information (FTI) are disclosed, as the law allows.
The laws that permit disclosure also require its protection.
We partner with each agency to protect federal tax information.
Our agency partners play a vital role in safeguarding FTI by building effective security controls into your processes, procedures, and systems.
You are responsible for ensuring the information is protected appropriately from the time you receive it until the time it is destroyed.
The American public expects two things from both of us.
First, we work together proactively to be as effective as possible, and second, we safeguard their personal data.
A good security awareness program is, by far, the most effective and the least expensive part of the overall security program.
For many of you, this is simply a refresher on disclosure awareness, while for others, this may be the first time you have been exposed to the concepts.
Before we move into the substance of the discussion, I would like to thank you for everything you do to protect the confidentiality of federal tax information.
I truly appreciate it.
Manager: Hello. I am Safeguards Manager, and I´ll be the moderator for this discussion.
I have extensive experience with the IRS and have worked in many capacities within the Safeguards office.
Joining me as the panel are the Chief of Safeguard Review Team (Review Chief), Information Technology Specialist (IT Specialist), and the Program Analyst (Analyst).
The Review Chief, Analyst and IT Specialist have all served as disclosure enforcement specialists in the safeguards operation before moving into their current positions.
We´re grateful for the opportunity to visit with you today.
We´ll be discussing several key concepts that are used in protecting federal tax information, or FTI.
It is up to us to protect this sensitive information while creating and cultivating confidence in our agencies.
So let´s get started.
We will begin our discussion today with a question we are often asked.
IT Specialist, what do we mean by federal tax information, or FTI?
IT Specialist: Manager, that is a very good question.
FTI consists of two things.
One, a tax return, and two, return information.
FTI can be either or both.
FTI is any return or return information received from the IRS or a secondary source such as Social Security Administration, Federal Office of Child Support Enforcement, Bureau of the Fiscal Services, or the Centers for Medicare and Medicaid Services.
FTI is also shared under agreements allowed by the statute or regulations.
Analyst: A tax return includes all amendments, supplements, supporting schedules, attachments, or lists filed on paper or electronically along with the return, such as Forms 1040, 941, 1120, and other informational forms, such as a Form 1099 or a W-2.
Manager: So, now we know what is considered FTI for the return.
What is return information?
Analyst: I would like to answer that, Manager.
Return information, in general, is any information collected or generated by the IRS regarding any person´s liability or possible liability.
The Internal Revenue Code defines return information very broadly.
It includes, but is not limited to, the return itself, as well as any information that the IRS obtained or developed that relates to the potential tax liability.
It could be from anywhere.
Review Chief: FTI includes the information extracted from a tax return, including names of dependents, the location of a business, the taxpayer´s name, address, and identification number.
Even if identifiers, such as name, address, and identification number are deleted from this information, it is still considered FTI.
IT Specialist: We need to emphasize that the definition of return information includes anything relating to a tax account.
Return information includes the status of whether return was filed, if it is being processed, if it is under examination, if it is subject to other investigation, or in collection status.
It also includes information contained on transcripts of the taxpayer´s account.
This information is all FTI.
Manager: What about the copies of tax returns that clients or their representatives have given to the agency to verify their data?
Are those returns considered FTI?
Review Chief: No, Manager. Returns from clients are not federal tax information.
Source is the key to knowing whether or not the data is FTI.
The information must be derived from the IRS or a secondary source, as previously mentioned, for it to be considered federal tax information.
This is what you need to remember.
If the source is your agency´s client or a client´s representative, it is not FTI.
If the source is the IRS or an IRS secondary source, the information is FTI.
Manager: IT Specialist, what happens when the information from the return is transferred to a different format, document, or computer application?
IT Specialist: Agency personnel often forget that any information derived from the FTI is considered federal tax information and must be safeguarded.
Derived FTI includes things like photocopies, scanned data, or information transcribed into a form, letter, application, or spreadsheet.
It could be something as basic as a sticky note where information from FTI was jotted down for quick reference.
The information on the sticky note then becomes FTI, which requires safeguarding.
Review Chief: When there is any doubt, ask yourself, where did the data originate?
If the answer is IRS or one of the secondary sources, it is FTI and must be safeguarded.
Manager: Analyst, what requires FTI to be kept confidential?
Analyst: Title 26 of the United States Code or Internal Revenue Code, section 6103, gives the IRS the authority to disclose FTI to federal, state, and local agencies.
It also dictates that the disclosed FTI must be held confidential.
IRS shares billions of tax records each year to increase compliance, enforcement, and service to taxpayers.
These records help agencies generate hundreds of millions of dollars in revenue and provide verification for those requesting assistance.
With all this information sharing comes great responsibility to protect it.
Manager: Analyst, disclosure is a running theme in law.
Please explain what the term "disclosure" means.
Analyst: The Internal Revenue Code defines disclosure as making known of return or return information to any person in any manner.
We must be mindful that when Congress gave IRS the authority to disclose FTI, it also provided IRS statutory provisions to protect the private information of U.S. citizens.
The provisions provide the foundation for safeguarding FTI, which is where agency personnel and the Office of Safeguards entered the picture.
Review Chief: The law only allows FTI to be disclosed to those who are authorized and who have a need to know.
Manager: Thank you, Review Chief.
IT Specialist, can you please tell us about Publication 1075 and why it´s important to the agencies who receive federal tax information?
IT Specialist: Publication 1075, Tax Information Security Guidelines for Federal, State, and Local Agencies, details the security requirements for all agencies that receive, process, store, or transmit FTI.
Publication 1075, for all intents and purposes, is the guiding document for the Office of Safeguards and our agency partners.
It provides the information needed to meet the strict requirements for requesting, receiving, safeguarding, and destroying FTI.
Analyst: The requirements within the publication originate from several different sources.
Internal Revenue Code, or IRC, Section 6103, IRS policy and procedures, and the National Institute of Standards and Technology Special Publication 800-53.
These requirements are designed for moderate-risk systems and are the backbone of information technology confidentiality requirements.
Review Chief: Each agency that receives federal tax information must become familiar with Publication 1075 and its requirements.
It outlines all the policies and procedures for safeguarding FTI within your agency.
Publication 1075 is periodically updated and published electronically.
The latest version is always available in the Safeguard section of the IRS´ website at IRS.gov.
Manager: Wow. That´s really helpful information, Review Chief.
IT Specialist, could you please tell us more about the Safeguard section of the IRS website?
IT Specialist: Certainly.
You can find comprehensive information by going to IRS.gov and searching for the "Safeguards Program" page.
Type the words "Safeguards Program" into the search box.
We update the website often, so I encourage you to visit the page frequently for most current information.
Our website has a lot of useful features and information you will need.
It includes alerts, technical information, and computer security requirements, which are documented in safeguards computer security evaluation matrices.
Review Chief: You will find recommendations on how to comply with Publication 1075 requirements, templates for internal inspections, and guidance on how to complete the forms.
Instructions for reporting unauthorized accesses, disclosures, or data breaches are on our site.
And a link to this video is on the webpage in case you need to revisit it or share it with new staff members.
Manager: That´s great information.
It sounds like that Safeguards website is a one-stop shop for all of the safeguarding information.
Now we are going to examine the key tenets of safeguarding.
The eight areas of focus are as follows -- recordkeeping, secure storage, restricting access to FTI, employee awareness and internal inspections, reporting requirements, disposal of FTI, need and use, and computer security.
Let´s begin with recordkeeping.
Analyst, can you please tell us a little bit about recordkeeping?
Analyst: Recordkeeping requires that each agency maintain a system of standardized records or logs for all FTI.
Records and logs come into play at the time that the FTI is received, and they must remain active until the FTI is destroyed.
The logs may be in paper format, or they may be electronic.
The recommended data elements for the logs and their retention schedule are listed in Publication 1075.
An agency must be able to show the movement of FTI on its logs as it flows through the process.
If you provide FTI to the next person in the process, you must log where it went.
And the next recipient, or the new recipient, must log that they received it.
Review Chief: Whether the FTI is on a computer system or on a piece of paper, it must be tracked on a log from receipt to disposal.
Manager: Thanks, Review Chief.
Secure storage is the second of the key tenets.
What are the requirements for secure storage of FTI?
Review Chief: Secure storage is based on the concept of minimum protection standards, or the two-barrier rule.
Basically, there must always be two barriers between someone who is not authorized to see the FTI and the information itself.
IT Specialist: Let´s talk a minute about storage of FTI.
Tangible items such as a piece of paper, folder, or CD are usually locked in a filing cabinet or secured in a locked office.
So, the locked filing cabinet and the locked office constitute your two barriers.
But during business hours, the FTI may need to be outside of the locked cabinet.
So, in this instance, an employee who is present at all times while the FTI is in use can serve as the second barrier.
This person should have their badge above their waist, indicating they are agency personnel.
Review Chief: The two-barrier rule applies to all agency locations.
It could be the headquarters office or an alternate work site if personnel are allowed to work at home or elsewhere outside the office setting, certainly, the computer facilities where mainframes, servers, routers, and switches are located, as well as off-site storage, where backup tapes are kept, and field offices.
Federal tax information housed in any location within an agency must have two barriers protecting it at all times.
IT Specialist: One of the things we commonly see when we do on-site reviews is a situation where an agency is looking at the two barriers from the outside in, beginning at the guards.
The two-barrier rule starts with the FTI and proceeds from the inside out.
In other words, start at the FTI and look for what prevents it from being accessed by someone who is not authorized.
It is likely that you´ will never identify the guards as one of your two barriers.
Remember, people enter your agency every day, going past the guards.
However, they are not allowed in the area where the FTI resides.
Look for the two barriers from the inside out.
Manager: Thanks, IT Specialist.
Again, that is helpful information.
The two-barrier rule is a very common question that we get when it comes to FTI and safeguarding FTI.
Why is limiting access, however, such a key part of an effective security program?
Analyst: Restricting access to FTI is based on the premise that only agency employees, agents, and contractors who have a need to know are allowed access to FTI.
Basically, need to know is based on position.
If you need federal tax information to complete your job, then you have a need to know.
Restricting access to the greatest extent possibly makes FTI less vulnerable.
IT Specialist: You can restrict access by locking paper in a file cabinet, by requiring key or card access to rooms where FTI is stored, and through a secure log-in and password process on the computer systems.
When mailing FTI, double package it to prevent exposure if the outer packaging is damaged.
Always be mindful of the need-to-know aspect, and grant access within your agency to only those who have that need.
Review Chief: In some agencies, contractors are not allowed access to FTI by statute.
In these agencies, contractors may have access to any of your agency data, but it is the agency´s responsibility to ensure the contractors never have access to FTI.
For example, if a contractor comes in to repair a computer, the contractor will need to be escorted at all times, and security controls must be in place protecting the FTI.
Manager: An essential practice in restricting access is a notification requirement to alert others that data is, indeed, FTI and is restricted.
How are agencies expected to provide notification?
Analyst: I´ll be glad to explain that, Kevin.
Labeling is an important component of restricting access to FTI, whether it´s stored electronically or on paper.
Labeling provides a warning that the data is restricted.
FTI must be clearly labeled as federal tax information and handled in such a manner that it is not misplaced or that it becomes available to unauthorized personnel.
Review Chief: Publication 1075 provides information on how to order labels for paper documents and backup tapes in the appropriate language needed for warning banners displayed on the screens of computers providing access to FTI.
It makes sense that labeling all FTI would deter unauthorized access.
Manager: We have been talking about the key tenets of safeguarding FTI for the last few minutes.
Obviously, it is important for those of us who have access to data to understand each of these tenets.
How does an agency impart that knowledge?
IT Specialist: Agencies are required to provide awareness training for their employees to help them gain an understanding of the agency´s security policies and procedures for safeguarding FTI.
The training must be provided before access to FTI is granted and annually thereafter.
The requirements for the training are in Publication 1075.
Analyst: Each employee who completes the training must sign a form acknowledging their understanding of the requirements to protect FTI and the sanctions for unauthorized browsing or unauthorized disclosure.
Your agency must retain these acknowledgement certificates according to the retention schedule in Publication 1075.
Manager: After the training, how does an agency verify those individuals are following the security policies and procedures for protecting FTI?
Review Chief: Agencies must conduct internal inspections which should be similar to our safeguards on-site reviews.
These inspections provide your agency with a way to identify its compliance with Publication 1075 requirements.
Inspections must be conducted at all locations where FTI resides.
IT Specialist: The time frames for conducting these inspections are listed in Publication 1075.
Templates are available on Safeguards´ webpage of IRS.gov.
These templates must be notated and included in the agency´s annual Safeguards Security Report.
Manager: Wow, another acknowledgement of the Safeguards’ website.
How does an agency report its safeguarding efforts to us?
Analyst: Each agency must submit an annual Safeguards Security Report (SSR).
The SSR describes the procedures established and used for safeguarding.
The SSR is certified by the head of your agency, indicating the agency´s compliance with safeguarding requirements.
Review Chief: Then, every six months, each agency submits a corrective action plan (CAP), which provides a status update on any findings from the on-site review.
CAP documents the corrective actions completed and those planned.
The IRS Safeguards Office tracks the status of all findings until they are closed.
IT Specialist: Advanced notification and approvals must be submitted 45 days before your agency secures contracting services or begins specific IT infrastructure changes.
As the IT environment changes, so do the requirements for notifications, so be sure and check our website and the current version of Publication 1075 to determine whether the activity your agency is considering requires a notification.
Analyst: We answer technical inquiries (TIs) that your agency sends via e-mail regarding the processes and procedures for safeguarding FTI.
Review Chief: If you discover a possible improper inspection or disclosure of FTI, and this could include a breach or security incident of any kind, the individual making the observation or receiving information must contact the Office of Safeguards immediately.
The contact should be made as soon as possible, but no later than 24 hours after the discovery.
Analyst: Your agency must notify the Office of Safeguards by e-mail.
Even if all information is not available about the incident, immediate notification is still the most important factor.
Review Publication 1075 for details on how to report data incidents.
IT Specialist: All reports, notifications, technical inquiries, and data incidents must be sent encrypted to SafeguardReports@IRS.gov or through secure data transfer if your agency has the capability.
Current templates and submission procedures are available on our website.
Manager: We talked earlier about recordkeeping from receipt to destruction.
Are there requirements for destroying FTI?
Review Chief: Absolutely.
As important as it is to track the FTI received, it is equally important to know when and what FTI has been destroyed.
The agency must document the destruction in their annual SSR and provide a sample of the log used to record it.
Analyst: FTI may be disposed of by destroying or returning it to the IRS, as outlined in Publication 1075.
As FTI is increasingly maintained in electronic systems, destruction requirements are continually changing.
Check our website regularly for any alerts and changes to these requirements.
Review Chief: Regardless of how the agency is destroying the FTI, the method must make it unreadable or unusable.
Manager: Another consistent theme seems to be logging, whether electronic or physical.
Analyst, can agencies use the FTI for any agency purposes once they receive it?
Analyst: No, Manager. They cannot.
The Internal Revenue Code is very direct on how agencies can use it.
They are prohibited from using FTI for any purpose other than that authorized by statute.
Before the agency receives FTI, the IRS must approve its intended use.
Part of the Safeguards on-site review is to verify that the data is being used as approved.
Manager: Deficiencies in computer security account for 98% of the weaknesses identified during Safeguards´ on-site reviews.
Computer security methods are constantly changing.
IT Specialist, can you tell us a bit about computer security and how it applies to safeguarding FTI?
IT Specialist: The focus of the computer security portion of the on-site review is based on requirements outlined in the National Institute of Standards and Technology Special Publication 800-53.
We review your agency´s IT security controls using evaluation matrices and automated testing tools.
We also examine written documentation and policies and procedures in your IT environment.
To be proactive with safeguarding, your agency can verify their IT systems receiving, processing, storing, or transmitting FTI are compliant with Publication 1075 requirements by using the Safeguards computer security evaluation matrices found on our website.
Review Chief: Logging and auditing are required to effectively capture all access, modification, deletion, and movement of FTI by each unique user.
This will identify any external breaches or suspicious activity.
IT Specialist: Automated testing is performed on various systems during an on-site review.
We use an industry-standard compliance and vulnerability assessment tool to evaluate the security of systems that store, process, transmit, or receive FTI.
This tool conducts configuration compliance checks using Center for Internet Security (CIS) benchmarks supplemented with IRS-specific requirements.
The audit files are available on our website.
Manager: Review Chief, are there any consequences for the misuse of FTI?
Review Chief: Yes. There are two criminal penalties associated with either or both unauthorized access or unauthorized disclosures of FTI.
This applies to individuals even after they are no longer employed with your agency.
There is a lifelong prohibition from disclosing federal tax information.
The most severe penalty is for unauthorized disclosure, which means that you were providing FTI to someone that is not entitled to have it.
The penalty is five years of imprisonment, a $5,000 fine, or both, plus the cost of prosecution.
Analyst: The penalty for unauthorized access is one year imprisonment, $1,000 fine, or both, again with the cost of prosecution.
Unauthorized access is reviewing the data when you are not entitled to look at it.
You can actually be guilty of both offenses and prosecuted for both unauthorized disclosure and unauthorized access.
Let´s not forget that taxpayers who are harmed by unauthorized access or unauthorized disclosure may seek civil damages.
The taxpayer may receive a minimum of $1,000 for each unauthorized access or disclosure or actual damages, whichever is greater, plus punitive damages and the cost of the action.
Review Chief: It is important to remember that you, not your agency, are liable for these penalties.
Manager: Wow, Review Chief. Those are very significant penalties.
I definitely wouldn´t want to run afoul of that.
In this segment, we will highlight the technical requirements that are specific to child support enforcement agencies.
The use of contractors is becoming more prevalent in government today.
Analyst, what do child support enforcement agencies that use contractors need to do to protect federal tax information?
Analyst: Child support enforcement agencies may disclose federal tax information to their agents and contractors.
IT Specialist: If the agency is disclosing the FTI to a contractor, it must include specific language in the contract.
You will find that language in Publication 1075, Exhibit 7, Contract Language for General Services.
This language officially notifies the contractor of their requirement to protect FTI.
It also advises of the criminal and civil penalties that will apply if data is misused.
Manager: Well, is the FTI that is disclosed to the noncustodial parent limited, as well?
Review Chief: A non-custodial parent has the right to receive his or her own information, even if it had come from IRS and is FTI.
There is no provision in the Internal Revenue Code that prohibits an agency from providing a noncustodial parent with their own federal tax information.
Manager: That makes sense.
If it is my data, I have the right to see it.
Child support is frequently an issue in court proceedings.
Are there limitations on what can be disclosed in court?
IT Specialist: In court proceedings, a child support enforcement agency may provide the amounts only after removing the source from all payments.
When the agency removes the source, that protects it from disclosure, even if the payment resulted from an IRS refund offset.
Remember, the source is the key.
Manager: Thank you, IT Specialist.
I would like to thank the panel for their discussion on this important subject of protecting federal tax information.
Their answers have given us insight into safeguarding.
We encourage you to visit our website and review the current revision of Publication 1075.
Remember, when you are successful, we are successful.
I would like to turn this back to the Associate Director to close out.
Associate Director: We all have a shared responsibility to ensure that federal tax information is disclosed only to those with a need to know and only used as authorized by statute or regulation.
We at the IRS are confident in your diligence, that you adhere to good security protocols, that you are as vigilant as we are about protecting FTI and using it appropriately.
As our IRS Disclosure Awareness Training video concludes, I encourage you at all times to ensure that the data you hold is secure and protected.
Please remember to follow the security requirements within your agency.
Thank you for your time, but most of all, thank you for your efforts to protect the confidentiality of federal tax information.
General session and session for state human resources agencies
The Office of Safeguards is working to update this resource, please refer to the information below until the video/podcast can be restored.
Associate Director: Hello. I am Associate Director from the IRS Office of Safeguards.
Welcome to Safeguards Disclosure Awareness Training.
The purpose of this video is to provide training for federal, state, and local agency employees, agents, and contractors.
The Office of Safeguards verifies compliance with 6103(p)(4) safeguard requirements.
It does this through the identification and mitigation of any risk of loss, breach, or misuse of federal tax information by over 300 external government agencies.
Each year, billions of pieces of FTI are disclosed, as the law allows.
The laws that permit disclosure also require its protection.
We partner with each agency to protect federal tax information.
Our agency partners play a vital role in safeguarding FTI by building effective security controls into your processes, procedures, and systems.
You are responsible for ensuring the information is protected appropriately from the time you receive it until the time it´s destroyed.
The American public expects two things from both of us.
First, that we work together proactively to be as effective as possible, and second, that we safeguard their personal data.
A good security awareness program is, by far, the most effective and the least expensive part of the overall security program.
For many of you, this is simply a refresher on disclosure awareness, while for others, this may be the first time you have been exposed to the concepts.
Before we move into the substance of the discussion, I would like to thank you for everything you do to protect the confidentiality of federal tax information.
I truly appreciate it.
Manager: Hello. I am Manager, and I will be the moderator for this discussion.
I have extensive experience with the IRS and have worked in many capacities within the Safeguards office.
Joining me as the panel are the Chief of Safeguard Review Team (Review Chief), Information Technology Specialist (IT Specialist), lead computer security reviewer, and Program Analyst (Analyst).
Review Manager, Analyst, and IT Specialist have all served as disclosure enforcement specialists in the safeguards operation before moving into our current positions.
We have all conducted on-site reviews.
We are grateful for the opportunity to visit with you today.
We will be discussing several key concepts that are used in protecting federal tax information, or FTI.
It is up to us to protect this sensitive information while creating and cultivating confidence in our agencies.
So let´s get started.
We will begin our discussion today with a question we are often asked.
IT Specialist, what do we mean by federal tax information, or FTI?
IT Specialist: Manager, that´s a very good question.
FTI consists of two things.
One, a tax return, and two, return information.
FTI can be either or both.
FTI is any return or return information received from the IRS or a secondary source such as Social Security Administration, Federal Office of Child Support Enforcement, Bureau of Fiscal Services, or the Center of Medicare and Medicaid Services.
FTI is also shared under agreements allowed by the statute or regulations.
Analyst: A tax return includes all amendments, supplements, supporting schedules, attachments, or lists filed on paper or electronically along with the return, such as Forms 1040, 941, 1120, and other informational forms, such as a Form 1099 or a W-2.
Manager: So now we know what is considered FTI for the return.
What is return information?
Analyst: I´d like to answer that, Manager.
Return information, in general, is any information collected or generated by the IRS regarding any person´s liability or possible liability.
The Internal Revenue Code defines return information very broadly.
It includes, but is not limited to, the return itself, as well as any information that the IRS obtained or developed that relates to the potential tax liability.
It could be from anywhere.
Review Chief: FTI includes the information extracted from a tax return, including names of dependents, the location of a business, the taxpayer´s name, address, and identification number.
Even if identifiers such as name, address, and identification number are deleted from this information, it is still considered FTI.
IT Specialist: We need to emphasize that the definition of return information includes anything relating to a tax account.
Return information includes the status of whether return was filed, if it is being processed, if it is under examination, if it is the subject of another investigation, or in collection status.
It also includes information contained on transcripts of the taxpayer´s account.
This information is all FTI.
Manager: What about the copies of tax returns that clients or their representatives have given to the agency to verify their data?
Are those returns considered FTI?
Review Chief: No, Manager. Returns from clients are not federal tax information.
Source is the key to knowing whether or not the data is FTI.
The information must be derived from the IRS or a secondary source, as previously mentioned, for it to be considered federal tax information.
This is what you need to remember.
If the source is your agency´s client or a client´s representative, it is not FTI.
If the source is the IRS or an IRS secondary source, the information is FTI.
Manager: IT Specialist, what happens when the information from the return is transferred to a different format, document, or computer application?
IT Specialist: Agency personnel often forget that any information derived from the FTI is considered federal tax information and must be safeguarded.
Derived FTI includes things like photocopies, scanned data, or information transcribed into a form, letter, application, or spreadsheet.
It could be something as basic as a sticky note where information from FTI was jotted down for quick reference.
The information on the sticky note then becomes FTI, which requires safeguarding.
Review Chief: When there is any doubt, ask yourself, where did the data originate?
If the answer is IRS or one of the secondary sources, it is FTI and must be safeguarded.
Manager: Analyst, what requires FTI to be kept confidential?
Analyst: Title 26 of the United States Code or Internal Revenue Code, section 6103, gives the IRS the authority to disclose FTI to federal, state, and local agencies.
It also dictates that the disclosed FTI must be held confidential.
IRS shares billions of tax records each year to increase compliance, enforcement, and service to taxpayers.
These records help agencies generate hundreds of millions of dollars in revenue and provide verification for those requesting assistance.
With all this information sharing comes great responsibility to protect it.
Manager: Analyst, disclosure is a running theme in law.
Please explain what the term "disclosure" means.
Analyst: The Internal Revenue Code defines disclosure as making known of return or return information to any person in any manner.
We must be mindful that when Congress gave IRS the authority to disclose FTI, it also provided IRS statutory provisions to protect the private information of U.S. citizens.
The provisions provide the foundation for safeguarding FTI, which is where agency personnel and the Office of Safeguards entered the picture.
Review Chief: The law only allows FTI to be disclosed to those who are authorized and who have a need to know.
Manager: Thank you, Review Chief.
IT Specialist, can you please tell us about Publication 1075 and why it´s important to the agencies who receive federal tax information?
IT Specialist: Publication 1075, Tax Information Security Guidelines for Federal, State, and Local Agencies, details the security requirements for all agencies that receive, process, store, or transmit FTI.
Publication 1075, for all intents and purposes, is the guiding document for the Office of Safeguards and our agency partners.
It provides the information needed to meet the strict requirements for requesting, receiving, safeguarding, and destroying FTI.
Analyst: The requirements within the publication originate from several different sources.
Internal Revenue Code, or IRC, Section 6103, IRS policy and procedures, and the National Institute of Standards and Technology Special Publication 800-53.
These requirements are designed for moderate-risk systems and are the backbone of information technology confidentiality requirements.
Review Manager: Each agency that receives federal tax information must become familiar with Publication 1075 and its requirements.
It outlines all the policies and procedures for safeguarding FTI within your agency.
Publication 1075 is periodically updated and published electronically.
The latest version is always available in the Safeguard section of the IRS´ website at IRS.gov.
Manager: Wow. That is really helpful information, Review Manager.
IT Specialist, could you please tell us more about the Safeguard section of the IRS website?
IT Specialist: Certainly.
You can find comprehensive information by going to IRS.gov and searching for the "Safeguards Program" page.
Type the words "Safeguards Program" into the search box.
We update the website often, so I encourage you to visit the page frequently for most current information.
Our website has a lot of useful features and information you will need.
It includes alerts, technical information, and computer security requirements, which are documented in safeguards computer security evaluation matrices.
Review Chief: You will find recommendations on how to comply with Publication 1075 requirements, templates for internal inspections, and guidance on how to complete the forms.
Instructions for reporting unauthorized accesses, disclosures, or data breaches are on our site.
And a link to this video is on the webpage in case you need to revisit it or share it with new staff members.
Manager: That´s great information.
It sounds like that Safeguards website is a one-stop shop for all of the safeguarding information.
Now we are going to examine the key tenets of safeguarding.
The eight areas of focus are as follows -- recordkeeping, secure storage, restricting access to FTI, employee awareness and internal inspections, reporting requirements, disposal of FTI, need and use, and computer security.
Let´s begin with recordkeeping.
Analyst, can you please tell us a little bit about recordkeeping?
Analyst: Recordkeeping requires that each agency maintain a system of standardized records or logs for all FTI.
Records and logs come into play at the time that the FTI is received, and they must remain active until the FTI is destroyed.
The logs may be in paper format, or they may be electronic.
The recommended data elements for the logs and their retention schedule are listed in Publication 1075.
An agency must be able to show the movement of FTI on their logs as it flows through the process.
If you provide FTI to the next person in the process, you must log where it went.
And the next recipient, or the new recipient, must log that they received it.
Review Chief: Whether the FTI is on a computer system or on a piece of paper, it must be tracked on a log from receipt to disposal.
Manager: Thanks, Review Chief.
Secure storage is the second of the key tenets.
What are the requirements for secure storage of FTI?
Review Chief: Secure storage is based on the concept of minimum protection standards, or the two-barrier rule.
Basically, there must always be two barriers between someone who is not authorized to see the FTI and the information itself.
IT Specialist: Let´s talk a minute about storage of FTI.
Tangible items such as a piece of paper, folder, or CD are usually locked in a filing cabinet or secured in a locked office.
So, the locked filing cabinet and the locked office constitute your two barriers.
But during business hours, the FTI may need to be outside of the locked cabinet.
So, in this instance, an employee who is present at all times while the FTI is in use can serve as the second barrier.
This person should have their badge above their waist, indicating they are agency personnel.
Review Chief: The two-barrier rule applies to all agency locations.
It could be the headquarters office or an alternate work site if personnel are allowed to work at home or elsewhere outside the office setting, certainly, the computer facilities where mainframes, servers, routers, and switches are located, as well as off-site storage, where backup tapes are kept, and field offices.
Federal tax information housed in any location within an agency must have two barriers protecting it at all times.
IT Specialist: One of the things we commonly see when we do on-site reviews is a situation where an agency is looking at the two barriers from the outside in, beginning at the guards.
The two-barrier rule starts with the FTI and proceeds from the inside out.
In other words, start at the FTI and look for what prevents it from being accessed by someone who is not authorized.
It´s likely that you´ll never identify the guards as one of your two barriers.
Remember, people enter your agency every day, going past the guards.
However, they are not allowed in the area where the FTI resides.
Look for the two barriers from the inside out.
Manager: Thanks, IT Specialist.
Again, that´s helpful information.
The two-barrier rule is a pretty common question that we get when it comes to FTI and safeguarding FTI.
Why is limiting access, however, such a key part of an effective security program?
Analyst: Restricting access is based on the premise that only agency employees, agents, and contractors who have a need to know are allowed access to FTI.
Basically, need to know is based on position.
If you need federal tax information to complete your job, then you have a need to know.
Restricting access to the greatest extent possibly makes FTI less vulnerable.
IT Specialist: You can restrict access by locking paper in a file cabinet, by requiring key or card access to rooms where FTI is stored, and through a secure log-in and password process on the computer systems.
When mailing FTI, double package it to prevent exposure if the outer packaging is damaged.
Always be mindful of the need-to-know aspect, and grant access within your agency to only those who have that need.
Review Chief: In some agencies, contractors are not allowed access to FTI by statute.
In these agencies, contractors may have access to any of your agency data, but it is the agency´s responsibility to ensure the contractors never have access to FTI.
For example, if a contractor comes in to repair a computer, the contractor will need to be escorted at all times, and security controls must be in place protecting the FTI.
Manager: An essential practice in restricting access is a notification requirement to alert others that data is, indeed, FTI and is restricted.
How are agencies expected to provide notification?
Analyst: I will be glad to explain that, Manager.
Labeling is an important component of restricting access to FTI, whether it´s stored electronically or on paper.
Labeling provides a warning that the data is restricted.
FTI must be clearly labeled as federal tax information and handled in such a manner that it is not misplaced or that it becomes available to unauthorized personnel.
Review Chief: Publication 1075 provides information on how to order labels for paper documents and backup tapes in the appropriate language needed for warning banners displayed on the screens of computers providing access to FTI.
It makes sense that labeling all FTI would deter unauthorized access.
Manager: We have been talking about the key tenets of safeguarding FTI for the last few minutes.
Obviously, it is important for those of us who have access to data to understand each of these tenets.
How does an agency impart that knowledge?
IT Specialist: Agencies are required to provide awareness training for their employees to help them gain an understanding of the agency´s security policies and procedures for safeguarding FTI.
The training must be provided before access to FTI is granted and annually thereafter.
The requirements for the training are in Publication 1075.
Analyst: Each employee who completes the training must sign a form acknowledging their understanding of the requirements to protect FTI and the sanctions for unauthorized browsing or unauthorized disclosure.
Your agency must retain these acknowledgement certificates according to the retention schedule in Publication 1075.
Manager: After the training, how does an agency verify those individuals are following the security policies and procedures for protecting FTI?
Review Chief: Agencies must conduct internal inspections which should be similar to our safeguards on-site reviews.
These inspections provide your agency with a way to identify its compliance with Publication 1075 requirements.
Inspections must be conducted at all locations where FTI resides.
IT Specialist: The time frames for conducting these inspections are listed in Publication 1075.
Templates are available on Safeguards´ webpage of IRS.gov.
These templates must be notated and included in the agency´s annual Safeguards Security Report (SSR).
Manager: Wow, another acknowledgement of the Safeguards’ website.
How does an agency report its safeguarding efforts to us?
Analyst: Each agency must submit an annual Safeguards Security Report.
The SSR describes the procedures established and used for safeguarding.
The SSR is certified by the head of your agency, indicating the agency´s compliance with safeguarding requirements.
Review Chief: Then, every six months, each agency submits a corrective action plan, which provides a status update on any findings from the on-site review.
This documents the corrective actions completed and those planned.
The IRS Safeguards Office tracks the status of all findings until they are closed.
IT Specialist: Advanced notification and approvals must be submitted 45 days before your agency secures contracting services or begins specific IT infrastructure changes.
As the IT environment changes, so do the requirements for notifications, so be sure and check our website and the current version of Publication 1075 to determine whether the activity your agency is considering requires a notification.
Analyst: We answer technical inquiries (TIs) that your agency sends via e-mail regarding the processes and procedures for safeguarding FTI.
Review Manager: If you discover a possible improper inspection or disclosure of FTI, and this could include a breach or security incident of any kind, the individual making the observation or receiving information must contact the Office of Safeguards immediately.
The contact should be made as soon as possible, but no later than 24 hours after the discovery.
Analyst: Your agency must notify the Office of Safeguards by e-mail.
Even if all information is not available about the incident, immediate notification is still the most important factor.
Review Publication 1075 for details on how to report data incidents.
IT Specialist: All reports, notifications, technical inquiries, and data incidents must be sent encrypted to SafeguardReports@IRS.gov or through secure data transfer if your agency has the capability.
Current templates and submission procedures are available on our website.
Manager: We talked earlier about recordkeeping from receipt to destruction.
Are there requirements for destroying FTI?
Review Chief: Absolutely.
As important as it is to track the FTI received, it is equally important to know when and what FTI has been destroyed.
The agency must document the destruction in their annual SSR and provide a sample of the log used to record it.
Analyst: FTI may be disposed of by destroying or returning it to the IRS, as outlined in Publication 1075.
As FTI is increasingly maintained in electronic systems, destruction requirements are continually changing.
Check our website regularly for any alerts and changes to these requirements.
Review Chief: Regardless of how the agency is destroying the FTI, the method must make it unreadable or unusable.
Manager: Another consistent theme seems to be logging, whether electronic or physical.
Analyst, can agencies use the FTI for any agency purposes once they receive it?
Analyst: No, Manager. They cannot.
The Internal Revenue Code is very direct on how agencies can use it.
They are prohibited from using FTI for any purpose other than that authorized by statute.
Before the agency receives FTI, the IRS must approve its intended use.
Part of the Safeguards on-site review is to verify that the data is being used as approved.
Manager: Deficiencies in computer security account for 98% of the weaknesses identified during Safeguards´ on-site reviews.
Computer security methods are constantly changing.
IT Specialist, can you tell us a bit about computer security and how it applies to safeguarding FTI?
IT Specialist: The focus of the computer security portion of the on-site review is based on requirements outlined in the National Institute of Standards and Technology Special Publication 800-53.
We review your agency´s IT security controls using evaluation matrices and automated testing tools.
We also examine written documentation and policies and procedures in your IT environment.
To be proactive with safeguarding, your agency can verify their IT systems receiving, processing, storing, or transmitting FTI are compliant with Publication 1075 requirements by using the Safeguards computer security evaluation matrices found on our website.
Review Chief: Logging and auditing are required to effectively capture all access, modification, deletion, and movement of FTI by each unique user.
This will identify any external breaches or suspicious activity.
IT Specialist: Automated testing is performed on various systems during an on-site review.
We use an industry-standard compliance and vulnerability assessment tool to evaluate the security of systems that store, process, transmit, or receive FTI.
This tool conducts configuration compliance checks using Center for Internet Security benchmarks supplemented with IRS-specific requirements.
The audit files are available on our website.
Manager: Review Chief, are there any consequences for the misuse of FTI?
Review Chief: Yes. There are two criminal penalties associated with either or both unauthorized access or unauthorized disclosures of FTI.
This applies to individuals even after they are no longer employed with your agency.
There is a lifelong prohibition from disclosing federal tax information.
The most severe penalty is for unauthorized disclosure, which means that you were providing FTI to someone that is not entitled to have it.
The penalty is five years of imprisonment, a $5,000 fine, or both, plus the cost of prosecution.
Analyst: The penalty for unauthorized access is one year imprisonment, $1,000 fine, or both, again with the cost of prosecution.
Unauthorized access is reviewing the data when you are not entitled to look at it.
You can actually be guilty of both offenses and prosecuted for both unauthorized disclosure and unauthorized access.
Let´s not forget that taxpayers who are harmed by unauthorized access or unauthorized disclosure may seek civil damages.
The taxpayer may receive a minimum of $1,000 for each unauthorized access or disclosure or actual damages, whichever is greater, plus punitive damages and the cost of the action.
Review Chief: It is important to remember that you, not your agency, are liable for these penalties.
Manager: Wow, Review Chief. Those are very significant penalties.
I definitely wouldn´t want to run afoul of that.
In this segment, we will highlight the technical requirements that are specific to human services agencies.
The use of contractors is becoming more prevalent in government today.
Analyst, how does this affect human services agencies?
Analyst: By statute, human services agencies are not permitted to redisclose federal tax information to contractors.
This makes their safeguarding requirements very different from other state agencies.
Review Chief: Let me emphasize this point.
Human services agencies cannot allow contractors or agents access to federal tax information.
Manager: Well, Review Chief, what is the primary area of concern we have identified with these agencies?
Review Chief: Our human services agencies ask about the eligibility determination letters.
These letters are sent to gather information from a third party -- for example, a bank.
The agency is trying to verify the information they received from the IRS, and often FTI is included in the letter.
The third party, the bank, completes the requested information and returns it to the agency.
If the letter contained FTI when it was sent, and the third party responds to that same letter, then it is FTI when it comes back to the agency.
All FTI, including the response letter, must be safeguarded from the time the agency receives it until the time it is destroyed.
IT Specialist: That´s right, Review Chief.
If the agency does not want to be concerned about safeguarding the letter returned by the third party, there is another way they can manage this type of situation.
We recommend the agency provide a separate document for the third party to respond with the information requested.
Analyst: The separate document can stand alone as third-party verification.
Although the third party may have provided personally identifiable information in the response, it did not originate with the IRS, and it is not FTI.
It needs to be protected, but that protection is separate from the safeguarding procedures in Publication 1075.
Review Chief: To recap, if the third party writes the information on a separate document and the source is the third party´s own records, it is not FTI and is not subject to safeguarding requirements.
Manager: Thanks again, Review Chief.
I would like to thank the panel for their discussion on this important subject of protecting federal tax information.
Their answers have given us insight into safeguarding.
We encourage you to visit our website and review the current revision of Publication 1075.
Remember, when you are successful, we are successful.
I would like to turn this back to the Associate Director to close out.
Associate Director: We all have a shared responsibility to ensure that federal tax information is disclosed only to those with a need to know and only used as authorized by statute or regulation.
We at the IRS are confident in your diligence, that you adhere to good security protocols, that you are as vigilant as we are about protecting FTI and using it appropriately.
As our IRS Disclosure Awareness Training video concludes, I encourage you at all times to ensure that the data you hold is secure and protected.
Please remember to follow the security requirements within your agency.
Thank you for your time, but most of all, thank you for your efforts to protect the confidentiality of federal tax information.
Building new systems
The videos present safeguards systems development aids to comply with Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies PDF security requirements when building a new application on which federal tax information (FTI) will reside or new process which will use FTI.
Session 1 for all agencies building new systems
- Safeguards 1 Building New Systems
The Office of Safeguards is working to update this resource, please refer to the information below until the video/podcast can be restored.
EXECUTIVE TECH ADVISOR: Hello.
I am Executive Tech Advisor of the IRS Office of Safeguards.
We are responsible for ensuring the protection of federal tax information, or FTI as you will hear it referred to, which the IRS provides to local, state, and federal agencies.
While the IRS has an oversight role in protecting FTI, our agency partners receiving the data play the most important role.
Each of the more than 300 agencies who receive FTI from the IRS must build effective security controls into their processes, procedures, and systems to ensure that the confidentiality of tax information is continuously protected from the time of planning for the receipt of FTI throughout its life cycle until the FTI is destroyed or returned to the IRS.
You and I, your agency and the IRS, are in this together.
We must be successful in our efforts to guard the security of FTI.
Neither of us can afford the fallout that comes from unauthorized disclosure of federal tax information.
The American public expects two things from both of us - first, that we protect the right to the privacy and confidentiality of their tax information and, secondly, that we work together proactively to be as efficient as possible.
When we are exchanging their sensitive financial information, we must ensure that their personal data is not inappropriately shared with others.
As part of working in tandem to protect FTI, we routinely discuss with agencies the security requirements to include in new processes, procedures, or policies that they may be building.
Many times, the new processes or procedures are needed due to changes in the data an agency may be receiving or because system improvements have afforded an agency the opportunity to change the way they do business.
Anything Safeguards can do on the front end to partner with an agency designing and building a new application processing FTI is in all our best interests.
Many agencies are planning to replace their old Legacy systems in the coming years.
So, we hope that you find the information in this video useful.
This information is designed to assist local, state, and federal agencies in designing and building a new application containing FTI.
It will cover key elements an agency should include for data protection.
Before we move into the substance of our discussion, let me just say thank you for everything you do to protect the confidentiality of federal tax information.
I truly appreciate it.
SENIOR IT TECH ADVISOR: Hi.
I'm Senior IT Tech Advisor, and I'll be moderating our discussion today.
I'm Senior IT Tech Advisor, in the IRS Office of Safeguards.
Joining me on the panel today are CSR1, the project manager for our office, and CSR2, the project lead from our contractor for computer security support.
Today we want to talk about building Safeguard requirements into the design and implementation of new applications which will contain federal tax information.
Okay.
Let's get started.
Before we get too far, CSR1, can you describe for us what is federal tax information (FTI)?
CSR1: Sure.
Return and return information that we provide to an agency is federal tax information.
The way to tell whether it's federal tax information or not is whether the IRS is the source.
Now, there's sometimes that we're the source, but we're not actually the delivery mechanism that the data comes through.
For instance, refund-offset information is provided to agencies from the Bureau of the Fiscal Service, a sister agency within Treasury, or sometimes it comes from Social Security Administration directly instead of from us even though it is our data.
So, it comes down to, was the IRS the source of the data?
And if we were, then it's federal tax information that has to be protected.
And federal tax information never loses its identification or integrity as federal tax information.
From receipt to destruction, it remains federal tax information.
SENIOR IT TECH ADVISOR: So, there is no length of time that would make something no longer federal tax information?
CSR1: No, sir.
It comes back to source.
If it came from us, then it is federal tax information.
SENIOR IT TECH ADVISOR: CSR2, I have heard a lot about the system-development life cycle.
Please tell me about what it is and how it works.
CSR2: Sure.
The system-development life cycle is really a process that guides system-development projects from the inception of the business need all the way through until when that system reaches its end of life and needs to be disposed of.
In order to be most cost-effective in building security, the security elements really need to be built in at the initiation of the system life cycle so that you are able to identify risk and address it as you progress through those phases of the system-development life cycle, hopefully being able to mitigate that risk at a lower cost than what we typically see as it being added on towards the end of the life cycle.
CSR1: We get a lot of inquiries from agencies who are now trying to retrofit (upgrade) security onto an existing system.
SENIOR IT TECH ADVISOR: So, what you're saying is they need to build it in from the beginning.
CSR2: Yeah.
Throughout every phase of the life cycle, there should be defined security tasks that need to be performed before you actually move on to the next phase.
So, by doing that, you're able to build requirements early into the design and make sure that the security features are functioning properly and doing what they're supposed to be doing before you go and try to deploy the system.
SENIOR IT TECH ADVISOR: So, CSR2, any agency that is looking to build a new application needs to consult their system security policy?
CSR2: Yeah, that is correct.
The security policy is really the foundation or the cornerstone of how security should be designed and implemented in any system.
The policy should lay out the goals for confidentiality, integrity, availability, and generally drive the security requirements that will be built into the system.
Now, Publication 1075 is that security policy for any system that is going to receive, store, process, or transmit FTI.
SENIOR IT TECH ADVISOR: Is there anything that application developers need to know that is addressed within Publication 1075?
CSR2: Sure.
I mean, the application developers or system integrators, depending on the type of project, should really be educated on Publication 1075 and be very familiar with the requirements therein, as well as just general security engineering principals or secure coding principals.
CSR1: And if the system engineers or the application developers are going to want to do any kind of testing, then they're going to need to notify the IRS because they have to have our approval to use federal tax information in a preproduction environment.
Because usually don't we see, CSR2, that they are really not as secure as a production environment?
CSR2: Yeah, typically the preproduction environment, because of the nature of how it is used for testing, is not secured like a production environment is.
So, we have this process in place to allow the IRS to learn some information about how the agency plans to use that federal tax information in their preproduction environment, whether it's for testing, development activities, staging, that kind of thing.
It allows us to understand a little bit how they're going to use it and what controls are going to be in place, so we have an assurance level that the data is protected while it is in that environment.
CSR1: Even what they're going to do when they're done?
CSR2: Correct.
SENIOR IT TECH ADVISOR: CSR2, are there any specific requirements that are in place or need to be in place as it relates to identification and authentication?
CSR2: Yes, there are.
Any system that's going to receive, store, process, or transmit FTI must uniquely identify every user.
And then there are minimum password requirements that have to be met, as well - things like a minimum of eight characters for a password, complex passwords using special characters, alpha-numeric characters, that kind of thing.
Password aging - ensuring that passwords expire after a certain time period and users are required to change them frequently.
Additionally, if there is any remote access to a system with federal tax information - let's say VPN access, an employee working at home - that remote connection needs to have two-factor authentication, which is a stronger authentication mechanism than your normal password.
CSR1: We get asked all the time, "What constitutes two-factor authentication?" Can you explain it a little bit?
CSR2: Sure.
Like I said, it's just a stronger way to verify the identity of the user - that they are who they say they are.
So, it's using a combination of two out of three possible factors - something you have, you know, like a smart-card like your HSPD-12 card or a token, a one-time password token, something you know, which is typically your password or a pin number or something like that, and then the third could be something you are, a biometric like your fingerprint.
SENIOR IT TECH ADVISOR: CSR1, can you talk about "need to know" as it relates to federal tax information?
CSR1: Certainly.
"Need to know" comes down to you should only have access to federal tax information if you have a need to know because of what you do for a living.
So, when we give information to an agency and they're looking to see who needs to have access to it, it should be based on those employees' positions - what they actually do, what they need to do their job.
The other piece of "need to know" is what does the statute say that you're allowed to use it for?
Because if the statute says - the statute under which we give information - says that they can only use for tax administration, for instance, then using the federal tax information for anything else violates that premise.
So, it is, first, is it being used for what the statute intended it to be used for, number one, and then, number two, who has a need to know?
We'll see sometimes where different case workers or different groups of employees within an agency have a different need for different information based on what they do for a living.
So, this group of employees may need five different data elements, and this group over here needs a different set of data elements.
So, setting those up as "need to know" only within those particular data elements is what you need to do for systems development.
This is, again, a place that we need to have focus by both the IT staff and by the program staff to work together to identify what those groups are and what their actual need for data is.
It should be kept to a minimum.
The employee needs to be given only the FTI they need to do their job.
And in an application-development sense, then building role-based applications so that the access controls that CSR2 may have based on what he does may be different than the access controls that you do because you do a different kind of position allows, then, that the employees are gaining access only to the different pieces of federal tax information that they really need to do their job.
SENIOR IT TECH ADVISOR: CSR1, how do you actually know - how does a user know that they are even looking at federal tax information?
CSR1: Hopefully, they have been trained by their agency.
That should be the first part.
When CSR2 talked earlier about access and about identification, hopefully part of that, as well, is understanding how the data flows and understanding that this is the data that I am looking at.
There also is a warning banner that should be in place.
Now, the IRS prefers that the warning banner be as close to the application that actually contains federal tax information as possible, but somewhere between the time that the employee logs on to when they access federal tax information, there needs to be a warning banner.
And that warning banner needs to cover four things.
It needs to say that they are about ready to access U.S. government information, that they're subject to auditing or oversight for being in the information, that unauthorized access is prohibited, and that there are sanctions associated with that unauthorized access.
Now, we don't really care, to a large extent, what their warning banner says as long as it has those four components.
Some agency applications - they can put the warning banner right as you go in.
Others, the older Legacy systems - it may be much closer to the front, where the employee signs on for the first time that day they actually see it.
SENIOR IT TECH ADVISOR: Is there a place where an agency can go if they don't have a warning that's sufficient that they can get information to add to or create their own warning?
CSR1: Sure.
There are a couple of places, actually.
An agency could go out on IRS.gov and go to the Safeguards Program's website.
And out on the website there is a copy of warning banners.
There are three different ones that they could pull directly off the website.
The other thing they could do is look at Exhibit 8 in Publication 1075.
It also has three different versions of the warning banner.
Now, those warning banners start fairly big, and they go down to smaller text.
They were deliberately done that way so that if there are space limitations or character limitations that an agency would have, they would be able to use the one that works best for them.
But one thing, CSR2, that we also need to probably mention is not only does that warning banner need to be where the end users are coming in, but it needs to be where the system administrators and those back-end folks are, as well.
CSR2: We often focus so much on the end-user access that we forget about the database administrator or the server-operating-system administrator.
You know, they have access to that data, as well, because of their job function.
So, they need that same warning banner to be in place on their log-ins.
SENIOR IT TECH ADVISOR: CSR2, you're saying there is no distinction in terms of the application of the statutory rules between the end user and the front-end user?
CSR2: Right.
Even though they are performing different job functions, per se, they all have access to federal tax information, and they have that need to know to access the federal tax information.
So, they need that warning banner.
CSR1: In fact, the folks on the back end generally have access to more data because a systems administrator can see potentially all the data that they have that is federal tax information.
So, that's why it is so important that we make sure that both the users on the front end and then the folks that are on the back end, the system administrators, database administrators, all have a warning banner when they come in.
SENIOR IT TECH ADVISOR: And that makes that training that you mentioned paramount.
CSR1: Exactly!
SENIOR IT TECH ADVISOR: CSR2, it seems like labeling and auditing go hand in hand.
Can you explain the auditing side?
CSR2: Sure.
So, auditing is a detective control that's used to really identify potential unauthorized access to FTI or security anomalies that are occurring on the system.
Publication 1075 requires auditing of any access, modification, deletion, or update to federal tax information.
So, in order to properly identify those transactions that contain federal tax information that need to be audited, that audit trail needs to key off that label of federal tax information in order to be, you know, properly captured.
Now, it's not just enough to capture audit logs, you know, volumes of disc with a bunch of audit records on it.
You know, it doesn't do us a whole lot of good unless we're actually looking at it, reviewing it, trending, seeing, you know, what might be going on in the system, are there security anomalies, are there things that we need to investigate.
CSR1: Nobody can look at hundreds or thousands of lines of an audit record and look to say, you know, "Those five look suspicious." It's just not possible.
One of the things that Safeguards is looking to go to sometime in the next probably three to five years is what we're calling proactive auditing.
And it's basically taking your audit logs and running mathematical algorithms against it to be able to identify those trends, to be able to see if you have anomalies or to see if you have an employee doing something they shouldn't be because they're looking up somebody whose address is three doors down from theirs or they're looking up somebody that has the same last name - those types of things.
So, it is a requirement that we're starting to look at.
We've been working with a stakeholder group that we have to try to develop what would be the right thing to do to go down that path.
It will likely be three to five years before we get there.
So, folks that are building new systems now - labeling becomes even more critical because if it's not labeled correctly, then you're probably not generating the right audit logs.
And if you're not generating the right audit logs, then when you get to proactive auditing, you're going to be trending against data that may be a little quirky, and it'll be much more difficult.
So, all this ties together.
And it's all about protecting the data that we have and making sure that nobody is doing anything with it they shouldn't.
And, frankly, most of the agencies need to do this - but most of them do - with their own data, not just our data.
And so, it's all about - in a world today when we have identity theft and we have privacy concerns - making sure that our folks are doing the right thing with our data, as well as with the agency's data.
SENIOR IT TECH ADVISOR: Building upon the issue of auditing, is there a record retention that's required for keeping audit logs so you could potentially engage in this analysis and review?
CSR2: Yeah.
Publication 1075 requires that agencies retain their audit logs for seven years to support after-the-fact investigations.
The other point I wanted to make, too, was back to the concept we talked about earlier about needing auditing at multiple layers.
So, it's not enough just to audit at the application layer, for example.
You really want to audit at all those layers we talked about - at the application, at the database, and at the operating-system level.
SENIOR IT TECH ADVISOR: Why is that important?
CSR2: Well, back to what we talked about, you have different folks performing different roles.
The database administrator could potentially query that database directly through the database-management system without going through the front-end application.
So, you want to make sure you are capturing a record of all the possible access points to the federal tax information.
CSR1: That's why the auditing requirement talks about looking for modifications, deletions, additions for each unique user, because we need to see, as CSR2 said, both the front end and the back end in order to see if there's some type of trend or there's some type of anomaly that's going on.
SENIOR IT TECH ADVISOR: CSR2, let's continue with this notion of security but from a wider lens.
Coming from the outside, is encryption important in security?
CSR2: Absolutely.
Encryption is very important!
Publication 1075 actually requires that all FTI in transit, whether that's within your local area network or if you're going to send it somewhere beyond your local network - let's say maybe a remote connection or over the wide area network - be encrypted, as well.
The importance of encryption is just that it prevents people from eavesdropping on that connection and stealing that data, per se, while it's transmitted over the wire.
Now, this can be accomplished in a couple different ways depending on how you're making those transmissions.
At the application layer, let's say an agency wants to use FTP to move some data across the wire.
Well, we want them to use a secured FTP protocol so that we know that that data is encrypted while it is being transmitted.
Let's say they're using the Web to transmit traffic.
We want them to use SSL or transport layer security, TLS, to encrypt that data at the transport layer.
SENIOR IT TECH ADVISOR: We hear a lot in the news about computer viruses.
Are there specific things that agencies can do to protect themselves against viruses?
CSR2: Yes.
Agencies should employ layered security, or defense in depth, as it's referred to.
What this really means is just employing a segmented network that uses boundary-protection mechanisms at each network segment in order to properly control the flow of FTI from the point when it's received into the network perimeter all the way until it hits that segment where the FTI is present.
So, you want to have devices like firewalls and routers at the edge of those network segments inspecting that traffic inbound and outbound to make sure that only the legitimate traffic that is necessary for the FTI system is able to get to that system.
CSR1: And intrusion-alert-type software - is also handy, isn't it?
CSR2: Yeah.
You definitely want to have intrusion-detection or intrusion-prevention systems inspecting that traffic, monitoring it, looking for viruses and things of that nature, and alerting people to take action when an anomaly is alerted.
CSR1: One of the things that the August 2010 version of Publication 1075 did was put into play requirements if you're going to have a website that you have customers that can come in on, because obviously they're going to want to come in and get their information.
But we need you to have a tiered architecture if you're going to do that so the federal tax information isn't where anybody could get to it.
And you have to have strong passwords or a strong type of authentication so that if you're the customer coming in that we know that you are you.
And so that was one of the improvements that came into the August 2010 version of Publication 1075.
CSR2: Yeah, and you definitely never want to store any federal tax information on any server that's directly accessible from the web.
So, your web server, for example - you don't want to store data on there.
And that's the tiered architecture that CSR1's talking about breaking it up so that there are layers in between that end user who may be out on the Internet and where the data is actually stored.
SENIOR IT TECH ADVISOR: When agencies need specific configuration settings, where do they go to find it?
CSR2: Well, agencies are required to put in place mandatory configuration settings for systems that receive, store, process, or transmit FTI for the security settings on those systems.
Now, Publication 1075 itself doesn't go into the specific details of every platform technology and the specific configuration settings for that technology, but we have supplemented the publication with what we call the Safeguard Computer Security Evaluation Matrices, or SCSEMs that we refer to them as.
These are actually the testing vehicles that our team will use to conduct the on-site Safeguard reviews.
So, they are an excellent tool for the agency to use to harden their systems even in preparation for our review team coming out and conducting the review.
CSR1: Or even to go in and look - as far as continuous monitoring - to go in once a year and double-check, because we do update them sometimes if we've added requirements or if we've tweaked a bit.
And so an agency could use those on an annual basis simply for continuous monitoring.
They are out on the IRS.gov site.
They are on the bottom of the main landing page.
And we try to be very transparent and put everything up there that anyone could possibly need to be able to go in and use.
So, not only does it have the configuration settings in it, but they are great for hardening the system and they are great for being able to do continuous monitoring.
CSR2: Yeah.
I think we have over 20 different SCSEMs now at this point, all sorts of operating-system platforms - Windows, UNIX, Linux, mainframe security software, network devices.
It pretty much covers the whole gamut (range).
SENIOR IT TECH ADVISOR: And all those SCSEMs can be found on IRS.gov?
CSR2: Mm-hmm.
SENIOR IT TECH ADVISOR: That's great.
CSR1, how does an agency seek assistance when they need help?
CSR1: There are actually two ways I would recommend to agencies.
The first is to go check the IRS.gov website, especially there's an area out there for guidance by technical topic and see if someone else has asked the question.
Over the last several years, as different agencies have asked us different questions, we have taken answers and put up on the IRS.gov website, figuring if one agency had the question, somebody else may, as well.
But many agencies have very specific needs.
They need to talk to us about their environment - and everybody has a unique environment - to be able to say, "We need to do," or, "We want to do 'X,' 'Y,' and 'Z,' and will this work against the requirements of the Publication 1075?" What we suggest is that they send into the mailbox - the safeguardreports@IRS.gov mailbox - an e-mail that says, "We would like to talk to somebody on a conference call." And we do a lot of those conference calls where we just sit and talk with the agency.
"Tell us what you're looking to do, what you're wanting to do.
"Let's talk about what the Publication 1075 requirements are.
"Let's talk about the constraints "that are within your environment and figure out the “how,” if you will." The Publication 1075 will tell them the “what.”
It tells them what the requirements are, but much of the time the agency then needs to figure out the “how”, given their own environment.
So, they just need to send an e-mail in to the mailbox.
We'll set up a conference call, and we'll sit and chat with them.
SENIOR IT TECH ADVISOR: I think that's all the questions we had for today.
Thank you, CSR1, and thank you, CSR2, for joining us today.
We have covered a lot of information today, and I hope it's been helpful.
We look forward to working with you in the future.
Please don't hesitate to send your questions to our mailbox at safeguardreports@IRS.gov.
Thank you for joining us this afternoon.
EXECUTIVE TECH ADVISOR: Good security protocols are founded on the idea of continued vigilance such as completing disclosure-awareness training, conducting routine reviews of the agency's policies and processes, and reviewing information-technology systems to ensure access and password protocols are up to the appropriate standards.
I hope that you have found the video informative.
We look forward to working with you as you develop requirements for your new system or application.
If you need to discuss the Publication 1075 requirements, please do not hesitate to send an e-mail to our mailbox at safeguardreports@IRS.gov to request a conference call.
Again, thank you for your attention and for your efforts to protect the confidentiality of federal tax information.
Goodbye.
Session 2 for agencies building new processes or procedures
- Safeguards 2 Building New Processes or Procedures
The Office of Safeguards is working to update this resource, please refer to the information below until the video/podcast can be restored.
EXCUTIVE TECH ADVISOR: Hello.
I am Executive Tech Advisor of the IRS Office of Safeguards.
We are responsible for ensuring the protection of federal tax information, or FTI as you'll hear it referred to, which the IRS provides to local, state, and federal agencies.
While the IRS has an oversight role in protecting FTI, our agency partners receiving the data play the most important role.
Each of the more than 300 agencies who receive FTI from the IRS must build effective security controls into their processes, procedures, and systems to ensure that the confidentiality of tax information is continuously protected from the time of planning for the receipt of FTI throughout its life cycle until the FTI is destroyed or returned to the IRS.
You and I, your agency and the IRS, are in this together.
We must be successful in our efforts to guard the security of FTI.
Neither of us can afford the fallout that comes from the unauthorized disclosure of federal tax information.
The American public expects two things from both of us - first, that we protect the right to privacy and confidentiality of their tax information and, secondly, that we work together proactively to be as efficient as possible.
When we are exchanging their sensitive financial information, we must ensure that their personal data is not inappropriately shared with others.
As part of working in tandem to protect FTI, we routinely discuss with agencies the security requirements to include in new processes, procedures, or policies which they may be building.
Many times, the new processes or procedures are needed due to changes in the data an agency may be receiving or because system improvements have afforded an agency with the opportunity to change the way they do business.
Anything Safeguards can do on the front end to partner with an agency building or implementing new processes or procedures involving FTI is in all our best interests.
This information is designed to assist local, state, and federal agencies to be fully compliant with Publication 1075 requirements.
It will cover key elements an agency should include for data protection.
Before we move into the substance of our discussion, let me just say thank you for everything you do to protect the confidentiality of federal tax information.
I truly appreciate it.
SENIOR IT TECH ADVISOR: Hi.
I'm Senior IT Tech Advisor, and I will be the moderator for today's discussion.
I'm the Senior IT Tech Advisor, in the IRS Office of Safeguards.
Joining me on the panel today are CSR1, the project manager for our office, and CSR2, the project lead from our contractor for computer security support.
Today, we want to talk about building safeguarding requirements into the new processes, procedures, or policies which involve the use of federal tax information.
Okay.
Let's get started.
Before we get too far, CSR1, can you talk about what federal tax information (FTI) is?
CSR1: Sure.
Federal tax information is return and return information where the IRS is the source of the information that's provided to the state or federal agencies.
It always comes back to who was the source of the data.
Now, for some different types of agencies, the IRS isn't directly who provides the information to the agency.
For instance, there's the Bureau of the Fiscal Service, or BFS, which is the sister agency for Treasury, or Social Security Administration.
They process on our behalf, and so the agencies may actually receive it from those agencies instead of us.
But it is still our data.
The source is really what makes up federal tax information.
Federal tax information never loses its integrity as federal tax information.
So, once an agency receives it, it always is federal tax information as long as we are the source of that data.
SENIOR IT TECH ADVISOR: What are the circumstances when an agency will most likely be establishing a new process or procedure for FTI?
CSR1: Generally, there are two.
One would be if an agency is already an existing data-sharing partner with the IRS but they're receiving a new data set.
So, for some reason they're getting new data that they previously haven't had.
So, as they start using that data, they're going to have to come up with the process and procedure around that new data.
The other is if they're a new trading partner - they're someone that has never received federal tax information from the IRS before.
So, for those agencies, they're starting from scratch.
They don't have existing processes to build off.
They have to build them completely from scratch.
Senior IT Tech Advisor: On that note, any advice you would give to agencies starting down that path?
CSR2: Yeah, absolutely.
I mean, a great first step is to really get the IT support collaborating with the business side and have them come together.
It's a great opportunity to talk through what the data flow is going to be through your environment once you receive that data and really map it out.
A simple way to approach it could just be looking at who, what, when, where, why, and how.
You know, just ask yourself those questions.
Who is going to need access, you know, from what departments within the organization?
How are they going to get access, whether it's systemically or on paper?
Those simple questions are a great first start.
Senior IT Tech Advisor: CSR1, where should an agency begin with starting their process?
CSR1: First, they need to begin with getting themselves familiar with Publication 1075 since that puts all the requirements in place, and they need to be really familiar with this.
And then my second recommendation is to build off what CSR2 said - start with the process that you have set down with the IT and the program side and figure out what the data flow is going to be.
And the next step on the requirements is then the logging requirements.
Federal tax information has to be logged from the time it's received to the time it's destroyed.
And since you already know what the data flow is, determining where your logging opportunities are as the federal tax information goes from one person to the next, that is probably the easiest thing to do first.
And it also builds off the work you've already been doing to come up with what the data flow is.
Senior IT Tech Advisor: How would an employee know what data needs to be logged and what is FTI?
CSR2: What we are going to talk about here is labeling.
You can't really know if you have FTI unless there is a label on it that says such, so you can't really restrict access to something if the outside of it is not labeled properly for the recipient to understand what it is they have in their possession.
So, we are talking about labeling for paper media, as well as digital media.
So, any scanned copy or printed file - it needs to have some sort of label identifying it as federal tax information.
Now, you know, with over 300 agencies that Safeguards provides oversight for, we can't tell you how to do that for everybody.
So, we leave that part up to the agency to really figure that out.
But it's just that identifying label that's going to let someone know that they're handling federal tax information and that they need to take care when handling it.
CSR1: Building on what he is saying, for a piece of paper that has federal tax information - a screen print, if you will – there is a myriad of different ways that an agency can go about marking it or labeling it.
Literally they can take a pen and write across the top of it "federal tax information." They can use stamps.
And we know of several agencies that have a stamp that every time they print something, it gets stamped.
There are labels that we provide to the agencies - that's Notice 129 - which are like an address label that says that this document contains federal tax information.
Folders that contain federal tax information - you can put those Notice 129 labels on the front of them.
Backup tapes - You were talking about electronic media.
There are little, tiny - they're really tiny - Notice 129-Bs that are for the outside of backup tapes that says, "This contains federal tax information." So, regardless of whether it is an electronic media, which could be a backup tape, a server, whatever it may be...
CSR2: A hard drive.
CSR1: ... a hard drive, right, or it's a piece of paper or a file folder, it just needs to be marked as federal tax information.
The other thing that needs to be marked as federal tax information is actually the federal tax information on the screen that someone may see.
By having that marked and then you do a screen print, you will be able to identify exactly that that's federal tax information.
So, labeling is a really key concept.
SENIOR IT TECH ADVISOR: Does the IRS provide any tools for labeling that agencies can get their hands on?
CSR1: As I said, we have the Notices 129-A and B, which are basically to put on either backup tapes or paper.
What we normally suggest as far as a systems backup is that they use a naming convention.
So, they may use "FTI," for instance, somewhere in their naming convention, or they may use something that makes sense to them.
And it doesn't matter to us.
We don't really care what they do use.
They just need to somehow name it in such a way that they know that that's federal tax information.
SENIOR IT TECH ADVISOR: So, there is no wrong way to do it, per se, as long as you are in the constraints of what the rules require.
CSR1: Right.
As long as you label it, there is really no wrong way to do it.
SENIOR IT TECH ADVISOR: So, CSR1, can agencies use federal tax information for anything they'd like to use it for?
CSR1: No.
Agencies are provided federal tax information in accordance with Title 26, Section 6103, which is basically the disclosure law in the tax code.
In the disclosure law, it specifically says what they can use the data for.
So, the data that's provided to them - they have to use it only for that purpose that is provided to them.
For instance, the data that's provided to the tax administration agencies around the country - they can only use that data for tax administration.
They can't use it for anything else.
SENIOR IT TECH ADVISOR: Even if there is an efficiency that a state agency might feel they have a legitimate use that they could use that information for, but it's not stated in 6103, can they still use it?
CSR1: No.
If the authority under which they get the data doesn't cover whatever it is that they're wanting to use it for, then they're not allowed to use it.
The data's given to them for a very specific purpose, and they have to use it for that purpose.
That's basically the way Congress wrote the law.
SENIOR IT TECH ADVISOR: And that purpose only?
CSR1: And that purpose only.
SENIOR IT TECH ADVISOR: Are there other components that agencies need to consider when restricting access?
CSR1: There are a couple, actually.
One has to do with "need to know." "Need to know" is an underlying concept for disclosure, which is if you don't have a need-to-know federal tax information, then you shouldn't have access to it.
So, it comes down to - Think if you have two or three different groups of employees that do different tasks.
So, they use different federal tax information.
Each of those groups should have access to only the data elements that they actually need to be able to do their job, but they shouldn't have access to everything because they don't need everything.
So, "need to know" is a key concept when trying to decide who should have access to what pieces of federal tax information.
The whole "need to know" provision really needs to be looked at and followed.
And that's a place - back to the comment you made several minutes ago - about working together with the IT shop and the program side will help you determine who really does need to know.
The program side is going to be able to provide the information that this group of people need this group of information, and a different group may need a different group.
But if they don't talk to the IT side and be able to tell them exactly how they need those roles set up within their systems, then, again, you're having people that don't necessarily have access to the right federal tax information.
When you're developing your process, you need to make sure that the right information is provided to the right people for the purpose for which the data is given to them.
Now, of course, the other complication that comes in on the access side has to do with contractor access.
Some of the authorities by which an agency can receive federal tax information allow for contractor access, and some of them don't.
So, depending on the type of agency and whether they are allowed to have contractors or not, then access to contractors is another piece that would have to be figured out.
CSR2: And that's particularly important in an outsourced data-center environment, when your IT support may not be embedded within your agency, but it may be either run by the state IT department or, you know, outsourced to a commercial vendor.
CSR1: Right.
Absolutely.
SENIOR IT TECH ADVISOR: So, it sounds like there are several wrinkles.
I mean, just because an agency has access - is allowed access by the statute to federal tax information, everyone in that agency is not necessarily allowed to have access to everything.
CSR1: Absolutely.
SENIOR IT TECH ADVISOR: Individuals get that access on a need-to-know basis, and then there are even additional wrinkles within that, whether you're a contractor or you're a person who works for the agency itself.
Everyone is on that need-to-know, which is dictated by the statute.
CSR1: You know, an example of maybe what an agency needs to follow is what your and my access here at the IRS is.
We don't work in positions that need to have access to federal tax information.
So, we don't have access to federal tax information.
So, if an agency receiving federal tax information has folks like you and I, who, based on what we do every day all day, don't need to have access to federal tax information, then they shouldn't allow those employees to have access, as well.
SENIOR IT TECH ADVISOR: So, CSR1, if an agency contracts with a vendor, are there additional requirements that that agency must abide by since the vendor has access or potentially has access to federal tax information?
CSR1: There are two things that the agency needs to do.
The first is a 45-day notification to us.
It's a requirement out of Publication 1075.
They can follow the Exhibit 6 bullets and fill out their document and send it in to the mailbox.
What the 45-day notice does is it tells the IRS that the agency has contracted with a vendor that is going to have access.
What they tell us in their notification is basically what data they'll have access to and how they're going to protect it.
The other piece that the agency needs to do is ensure that the Exhibit 7 language, which is language that basically puts the contractor on notice, again, that they're going to have access to federal tax information and that there are sanctions associated with the misuse of federal tax information - that language needs to be part of the contract.
If they do those two pieces, then they should be fine.
The one thing to remember, though, as we talked about a few minutes ago, is some agency types are not allowed to have contractor access.
So, if you're one of those types of agencies and you put in a 45-day notice, we're going to deny it because you can't have contractor access to begin with.
SENIOR IT TECH ADVISOR: So, isn’t this a loophole?
This is just clarifying that you would like to add your contractor on to have access to do work that is consistent with the statute.
CSR1: Right, and that they're supporting your mission.
For instance, if you were a tax agency, that they're supporting your mission for tax administration.
Obviously there has to be support for what the agency is doing.
It puts us on notice that there are additional folks within that agency - their contractors - that have access to federal tax information.
CSR2: It also gives us an opportunity to talk to those agencies and understand what it is they are going to be doing in the outsource environment.
And, you know, maybe we can provide some insight into other questions or issues that that agency might have at that point.
SENIOR IT TECH ADVISOR: Are there instances where agencies aren't exactly clear on how to navigate writing this letter or what they need to do?
And if those instances arise, what do agencies do?
CSR1: The Exhibit 6 in Publication 1075 gives them bullet points to speak to.
The place we actually get the most questions is if an agency is hiring expert witnesses for the next year and they know they're going to use expert witnesses, but they don't know exactly whom they're going to hire and when they're going to hire them.
Then what we do is we have them go ahead and put the notification together and just in the notification don't say whom they are hiring and the dates and instead give us some information - add a paragraph, if you will - that talks about this is sort of a blanket for a particular - what we usually do is for a year.
And so, it is almost like a blanket 45-day.
And then later when they do hire someone who is an expert witness, they just send the notification in to the mailbox to say, "We hired an expert witness for these dates." And we just associate it with the approved 45-day.
But that is coming up more and more as we have folks that hire people like expert witnesses or even the computer end, where you know, you are going to have somebody in because you know you're going to break a server somewhere during the year, but you don't know exactly what vendor it is going to be.
And so, we do these blanket 45-days that are usually for a particular year for a particular type of task.
And then they just notify us whom they hired under that contract to come in.
SENIOR IT TECH ADVISOR: CSR1, what physical security controls should an agency be mindful of when it comes to storing federal tax information?
CSR1: The basic rule is "two barriers." There always needs to be two barriers between federal tax information and someone who is not authorized to see it.
In most instances, the easiest way would be putting the - you know, say this is federal tax information - locking it in a filing cabinet and then it is in a locked office.
In some instances, your space is such that you really don't have where you have multiple offices, so during the day, if the federal tax information is locked in the filing cabinet and the staff have a badge above their waist, then they could actually serve as a second barrier.
But generally, you just have to always have two barriers between the federal tax information and someone who is not authorized to see it.
And so, it counts for paper, but it also counts on the IT end.
If you have servers in a computer room, then you have to lock up your servers in such a way that you also have two barriers for those servers.
So, it is federal tax information regardless of whether it is electronic or whether it is paper.
That federal tax information always has to have two barriers.
CSR2: So, CSR1, in the instance where there is an outsource data center and you have multiple agencies being hosted in one data center, and it is not necessarily that everyone in that room is authorized for federal tax information, but they need to be there to do their job, does that second barrier instance where the badge can serve as a second barrier - does that still ring true there?
CSR1: No.
Good question.
No, it doesn't.
In those kinds of instances, then you need to come up with a different way to have your two barriers, especially if you have folks from different agencies that need to be in that computer room.
What we see most often is that an agency will lock their servers into the server rack and then they will lock the server rack and they keep control of the keys.
And they make sure that someone who is not authorized for federal tax information doesn't have those keys.
A lot of times, a secure storage isn't high-tech kind of answers.
Most of the time it is going to the low-tech answers to be able to make sure that whatever you're doing, you're building two barriers between someone who's not authorized to have federal tax information and the federal tax information.
The thing to remember is you always start at the federal tax information and work out.
Don't start at the outside door and work in.
Start at the federal tax information, whether it's a piece of paper or whether it's a server, and then work out to make sure that you have your two barriers in place.
SENIOR IT TECH ADVISOR: Let's build on that.
Say, for example, you have an agency that has the authority to have federal tax information - let's say it's the headquarters - and they want to send their information to a field office.
What do they do?
CSR1: They still have to keep two barriers in play.
So, they can double-envelope if it's a small package, if it's just paper.
They can put it in double-boxed - so, you put one cardboard box inside of another cardboard box.
You can use a locked container, so you put it in an envelope and then put it in some type of locked container.
You have to continue to have two barriers in place.
The other piece that has to be in place is that there needs to be a transmittal.
Generally, the transmittal needs to say, "We're sending this information from this place to that place." And there are actually three copies of the transmittal made.
One is retained by the person who is sending it.
The other two are sent - Say I'm sending it to you.
I will send you the double-wrapped information and two transmittals.
You would sign both transmittals, send me one back, and you would keep one.
So, both you and I would have a signed transmittal with both sets of signatures saying when it went and when it came back.
If for some reason you knew something was coming and you hadn't received it, then you could call me and I could trace through what I have on the transmittal.
And if I haven't received back the signed transmittal where you've signed for receipt, then I know it may not have been received - Excuse me.
I know you may not have received it.
And then I have to go check and find out where it is.
So, by having the transmittal form where it goes with the data and then it comes back, both of us, the recipient and the person sending, can make sure that there is no federal tax information that's lost in transit.
SENIOR IT TECH ADVISOR: And does that double wrapping also require double labeling?
CSR1: Yes.
It should be double labeled, as well.
SENIOR IT TECH ADVISOR: And why is the double labeling important?
CSR1: Because if the first box fails, the first envelope fails, you still have something there saying where it needs to go so that hopefully the federal tax information doesn't get lost in the mail or lost in transit.
That second address then ensures that hopefully, if the outside box or outside envelope gets torn, it is still going to get where it needs to be.
SENIOR IT TECH ADVISOR: So, once an agency is done with the FTI they have, how do they dispose of it?
CSR2: Right, so, this really depends on, first of all, what type of media it is and then what do they plan to do with that media, whether it is, you know, final destruction or if they plan to repurpose it.
So, for paper media, it needs to be shredded at 1 mm x 5 mm (0.04 in. x 0.2 in.), crosscut shredding.
So, that really prevents you from reading it or really even reconstructing that paper.
For electronic media such as backup tapes or hard drives, discs, things like that, if the agency intends to reuse that media for another purpose, the data needs to be cleared electronically, which means it needs to be - the tracks on that disc need to be overwritten at a minimum of three times in order to electronically clear that data before it is transitioned on to its next use.
Now, if they don't plan to use that media anymore, they first need to clear it in that same manner, but then they need to go through another step of destroying the media, either electronically degaussing (removing) or using other methods to destroy.
CSR1: Now, one of the things they also need to do is they need to test every third one to make sure that it really is clear.
It's sort of a random - You know, every third piece that they are going to go ahead and either degauss or just clear so that they can reuse they need to test to make sure that they really are clear.
SENIOR IT TECH ADVISOR: So, CSR1, once an agency builds its new procedure, documents it in writing, what's next?
CSR1: The real next part is training.
They need to make sure their employees understand that they have federal tax information and what they are going to do with it.
Obviously, training is a huge piece of protecting federal tax information because an employee can't be expected to protect federal tax information when they don't know what they have really is federal tax information.
And so once an agency has developed their procedures, they have put them into writing, they have distributed them to their employees, our recommendation is they go ahead and have some type of training with their employees, as well, especially over what is different from what they may have done previously now that they are using federal tax information to make sure that all of the protocols for protecting the federal tax information really have been told to the employee, the employee understands them, and they're ready to roll.
SENIOR IT TECH ADVISOR: So, we covered a lot of things.
In the event that an agency needs some additional help, how do they get assistance?
CSR1: There are actually two different ways that I would recommend an agency get assistance.
One, they can go out to the IRS.gov website that is Safeguards.
And if they will go into IRS.gov and then put "safeguard reports" in the search box, we should come up the second order down.
They click on that, and they'll be on our main landing page.
Off that landing page, there is a "technical topics" link that they can go into.
As agencies around the country have asked us questions over the last five years, we have created answers for them based on what their questions were.
And anytime we really thought that the answer was something that other agencies may need to see, we have gone ahead and put a lot of those technical topics up on IRS.gov.
So, that would be my first place to go and look to see if there's something up there already.
If not, the agency needs to send an e-mail to us - to safeguardreports@IRS.gov, the normal mailbox we use for everything - and ask their question.
Now, if it's something that they think is fairly simple and they're just asking for clarification, then they should just type it out, kind of lay out what they're asking, and send it in.
The other thing they can do is if they want a conference call - if what they're doing is complex and they really want to have a dialogue with us, again, they would send an e-mail in, but they need to say in their e-mail that, "We would like a conference call," and that, "This is basically our topic," so that we can staff it properly.
But we are more than happy to talk to the agencies.
CSR2 and I do dozens of these a month to sit down and help agencies as they're trying to figure out how.
Publication 1075 says this is what you have to do.
The agencies have to figure out the “how,” and we're more than happy to help agencies figure that out.
CSR2: Yeah, I think that's a great tool for agencies because we do get a lot of the same questions all the time, believe it or not.
But, you know, the answers are highly subjective.
So, it's really nice to just be able to talk through what their issues are in specific.
And the conference call, I think, is a great tool to do that.
CSR1: Well, CSR2 makes a great point because while there are generally only, you know, five or six ways for any given question to pretty much implement it, it's so constrained by the context of that agency - what kind of IT do they have, what kind of resources do they have, how are their offices laid out.
And all of those variables make an answer for one agency very different than an answer for another agency because it's all about context and circumstances.
So, we are more than happy to sit and talk with an agency, to be able to say, you know, "This is what you need to do," and then work it through with them if whether that really works in their environment or not.
SENIOR IT TECH ADVISOR: CSR1, thank you.
We have gone through a lot of information today, and we hope that it's been helpful.
We look forward to working with you in the future.
Please don't hesitate to send your questions to our mailbox at safeguardreports@IRS.gov.
Thanks for joining us this afternoon.
EXECUTIVE TECH ADVISOR: Good security protocols are founded on the idea of continued vigilance such as completing disclosure - awareness training, conducting routine reviews of the agency's policies and processes, and reviewing information-technology systems to ensure access and password protocols are up to the appropriate standards.
We hope that you have found the video informative.
We look forward to working with you as you develop new or revised requirements for working with FTI to accomplish your agency's key mission.
If you need to discuss the Publication 1075 requirements, please do not hesitate to send an e-mail to our mailbox at safeguardreports@IRS.gov to request a conference call.
Again, thank you for your attention and for your efforts to protect the confidentiality of federal tax information.
Goodbye.
Protecting federal tax information
Presentation designed to give you information on federal tax information and the laws that protect it.
Short (10 minute) video on the on the overall protection of federal tax information (FTI)
- Protecting federal tax information: A message from the IRS
The Office of Safeguards is working to update this resource, please refer to the information below until the video/podcast can be restored
Data security breaches and information losses make the headlines and nightly newscasts.
The public is extremely sensitive about the vulnerability of their confidential data.
They have serious and very legitimate worries about identity theft.
When leading businesses and well-respected public agencies lose personal data about their customers and employees, whether by theft, accident, or negligence, it does more than make the news.
It's an event that undermines the public's confidence in institutions they trusted.
Because of the job you perform, you are probably accustomed to working with confidential records and other personal information.
You also have access to and work with federal tax information.
That federal tax information is an important asset on which both you and your employer rely.
Like you, I work with federal tax information, or FTI, as it's known.
To safeguard sensitive personal and financial information about taxpayers’ FTI is protected by law.
That law imposes important obligations on you, just as it does on me and all other IRS employees.
This presentation is designed to give you information you need to know about federal tax information and the laws that protect it.
This material may not be news to you.
You may have heard it before, perhaps even many times before.
While the content may not be new, it is timely, and it is certainly relevant.
What you are going to hear will help you to confidently work with federal tax data, knowing what it is and how to protect it.
The very fact that you are working with FTI is evidence that we trust you and that your employer has a culture of confidentiality with rigorous safeguards in place to prevent data loss and misuse.
The legal provisions that allow IRS to disclose FTI to your employer also oblige it and each of its employees to protect it.
The disclosure basics I'll share with you in this presentation may be found in greater detail in the "IRS Disclosure Awareness Pocket Guide."
Publication 1075 is also an excellent source of information about federal tax information and how to protect it.
Both are available at irs.gov.
The law I have been referring to is found in the Internal Revenue Code, or Title 26 of the United States Code.
Code section 6103 contains a general prohibition against the disclosure of federal tax returns and return information.
This prohibition applies to you as someone having access to FTI.
The law limits your access to FTI and your disclosure of that information to certain circumstances specified in the law.
As examples, section 6103(d) is the specific point in the law that permits the IRS to disclose FTI to state and some city tax agencies for use in tax administration.
Section 6103(i) allows disclosure of FTI to the Department of Justice and others for the investigation and potential prosecution of non-tax federal crimes.
A section of the same law allows us to disclose FTI to the taxpayer and their authorized representatives, while other sections provide for disclosure of certain information to agencies for specified purposes.
The code provisions that govern disclosure of FTI to you and your employer are important because if it administers other programs, FTI can only be used for matters authorized by statute.
To have a sound understanding of your obligations, you need to know just exactly what you can and cannot disclose.
On a more basic level, it is also important to understand just exactly what the word "disclosure" means.
The law itself is the source for the definition of "return," "return information," and "disclosure."
While the definition of a return may seem obvious, let's go over what it means under the law, which tells us that ...
A return means any tax or information return, estimated tax declaration, or refund claim, including amendments, supplements, supporting schedules, attachments or lists, required by or permitted under the Code, which is filed with the IRS by, on behalf of, or with respect to any person.
Examples of returns include forms filed on paper or electronically, such as Forms 1040, 941, 1099, 1120, and W-2.
"Return information" is defined by law and is very broad in scope.
It includes the taxpayer's name, mailing address, and identification number, including social security number or employer identification number; any information extracted from a return, including names of dependents or the location of a business; information on whether a return was, is being, or will be examined or subject to other investigation or processing; information contained on transcripts of accounts; the fact that a return was filed or examined; investigation or collection history; or tax balance due information.
Your employer may receive returns and return information electronically or on paper.
But it is important to know that, regardless of format, FTI is confidential.
Which brings us to the third important definition we need to cover, and that is "disclosure," which the law defines as...
... making a return or return information known to any person in any manner.
We know you want to do the right thing, and that is why we are here.
We want to make sure that you are fully aware of your responsibilities and the potentially serious repercussions of ignoring those responsibilities.
Knowingly and willfully disclosing FTI to someone not authorized to receive it or willfully accessing tax data without a business need to do so, known as UNAX, are both criminal offenses subject to penalties.
Internal Revenue Code section 7213 specifies that willful unauthorized disclosure of returns or return information by an employee -- whether federal or state -- former employee, or contractor employee is a felony.
The penalty can be a fine of up to $5,000 fine or up to five years in jail or both, plus the costs of prosecution.
Under IRC section 7213A, willful unauthorized access or inspection -- UNAX -- of taxpayer records by an employee is a misdemeanor.
This applies to both paper documents and computerized information.
Violators can be subject to a fine of up to $1,000 and up to one year in prison.
In addition to criminal penalties, civil remedies may also be pursued by any taxpayer whose return or return information has been knowingly or negligently inspected or disclosed in violation of section 6103.
Section 7431 allows a taxpayer to institute action in district court for civil damages.
If the court finds there has been an unauthorized inspection or disclosure of FTI, the taxpayer may receive damages of $1,000 for each act of unauthorized access or disclosure or the actual damage sustained, if greater, plus punitive damages and costs of the action.
And that is where it really gets expensive.
Protect FTI by following the tips available in the "Disclosure Awareness Pocket Guide."
Publication 1075 is the definitive source for safeguard standards and procedures required to protect federal tax information.
A number of IRS resources are available to help you access, work with, and protect FTI.
IRS Safeguards staff are responsible for periodic reviews for compliance with these data protection requirements and for receiving and approving certain reports required by law.
IRS Data Services works with agencies in use of DIFSLA extracts.
The IRS Governmental Liaison keeps the lines of communication and cooperation open and active with state and some city tax agencies and some federal ones, as well.
The IRS Disclosure Office answers your questions and concerns about access to FTI.
We are here to help you when you need to check it out before you give it out.
Return to: Safeguards Program