The Treasury Inspector General for Tax Administration determined that the Internal Revenue Service's cybersecurity program is not effective because three of six core functions did not meet required maturity levels.
In an annual assessment required under the Federal Information Security Modernization Act of 2024, the office found that the IDENTIFY, PROTECT, and DETECT functions failed to meet the required Maturity Level 4, described as Managed and Measurable. The remaining functions—GOVERN, RESPOND, and RECOVER—were effective.
Security deficiencies remain despite some improvement in maturity ratings. In a sample of seven systems, six had critical vulnerabilities that were not remediated within the required 30 days, leaving taxpayer data vulnerable to inappropriate or undetected use, modification, or disclosure.
