IRS Security Faults Leave Taxpayer Data At Risk
coondoggie writes "In this tax season, when billions of dollars and tons of personal information is relayed to and from the government, it's more than disconcerting to hear that the Internal Revenue Service is still struggling to keep private information secure. A report out Friday from watchdogs at the Government Accountability Office says about 69% of the tax agency's previously noted security flaws remain unfixed and continue to jeopardize the confidentiality, integrity, and availability of the IRS's systems (PDF). The problems put the IRS at increased risk of unauthorized disclosure, modification, or destruction of financial and taxpayer information, the GAO concluded."
Shameful that any company would fail at these basic tasks. It would take any competent admin very little time to compose policies that would effectively handle most of these. the others would require procedural changes but why would they continue to let the issue go if they know it's an audit exposure? (no pun intended)
From TFA:
For example, the GAO stated that the IRS continues to:
* use passwords that are not complex,
* ineffectively remove application accounts in a timely manner for separated employees,
* allow personnel excessive file and directory permissions,
* allow the unencrypted transmission of user and administrator login information,
* install security patches in an untimely manner