Improvements Were Made in Installing Card Readers but Physical Security Deficiencies Remain
Why did we do this audit?Federal employees and contractors must use standard identification to access federally controlled facilities. When physical access controls are not effectively implemented, there is an increased risk of unauthorized entry to IRS sites, potentially leading to theft of taxpayer information, compromise of IRS’s systems and networks, or physical harm to personnel. What did we find?Some employees continued to access IRS facilities after beginning administrative leave. These employees were on administrative leave because they accepted a deferred resignation offer. Specifically, we determined that 2 percent (431 of 22,227) of these employees accessed IRS sites after the start of their administrative leave dates. These employees did not have an apparent business reason for accessing IRS sites. During this audit, we also followed up on recommendations we made in a 2023 report. We found that some were fully implemented, but a recommendation to ensure that all noncompliant card readers were replaced with and properly configured was not implemented. This has been delayed until October 2026 due to budget restrictions and staffing losses. For more information:
Having trouble viewing this email? View it as a Web page.
|
No comments:
Post a Comment