Search FCW


Subscribe Now!
Table of Contents
Business
BPM
CXOs
Columns
Columnists
Defense
E-Government
Elections 2008
Enterprise Architecture
Funding
Homeland Security
Health IT
IPv6
LOB
Management
Procurement
Privacy
Policy
Program Management
State and Local
Security
Technology
Telework
Workforce

More Topics
resourcecenter
Home
Letters to the Editor
Current Issue/Download
Print/Online Archives
Editorial Calendar
resourcecenter
Oracle Microsite
DISA Guidebook
GI: Network Mgmt
Green Computing
Tech Watch: COOP
PR: IT Security
Alliant Contract Guide
Tech Watch: Mobile IT
Content Library

More >>



Latest News
ADVERTISEMENT





 

TIGTA: Private debt collectors protect IRS taxpayer data

By Mary Mosquera
Published on March 27, 2008

Comment

Click here to comment on this article


Related story links

Private collection agencies adequately protected taxpayer data

Taxpayer advocate: IRS may shortcut taxpayer rights to reduce tax gap

House panel to look into IRS’ use of private tax collectors


Newsletters

You might also be interested in these FCW newsletters:

Daily
Management
Security

To learn more, click here.


The two private collection agencies that the Internal Revenue Service hired to pursue delinquent taxpayer debt put in place adequate computer controls to protect taxpayer data, the Treasury Inspector General for Tax Administration said in a report released today.

The contractors, Pioneer Credit Recovery and CBE Group received the taxpayer data files securely from IRS and secured them satisfactorily on their systems, TIGTA said. The contractors also controlled their workstations to prevent unauthorized copying of taxpayer information to removable media or transfer through e-mail. They maintained audit trails and performed periodic reviews, including identifying unauthorized access to the taxpayer data.

Although the contractors do not delete taxpayer files or remove them from their systems once they close a case or IRS recalls it, the debt collectors protected the data by restricting access to taxpayer data files to only necessary employees, said Michael Phillips, deputy inspector general for audit.

“Inadequate security controls over taxpayer data would create increased risks of unauthorized access, misuse, disclosure, modification or destruction of taxpayer data,” he said.

Critics, such as the National Taxpayer Advocate, the National Treasury Employees Union and some lawmakers, have faulted IRS for contracting out the collection of taxpayer debt because it can put taxpayer privacy at risk and is an inefficient use of government funds.

But TIGTA said that the private debt collectors must assure that their computer systems comply with the Federal Information Security Management Act and the guidance developed by the National Institute of Standards and Technology to implement security controls that govern systems and communication protection, access controls and audit records.

“Each contractor implemented a best practice that should be considered by current and future private collection agencies,” Phillips said.

One contractor requires a second password, in addition to a standard username and password, before access to the contractor’s collection application is granted. This second password is generated through a password token device, small enough to fit on a key ring, which generates and displays a new password every 60 seconds. The other contractor places files downloaded from the IRS on a dedicated server.

As of February, IRS had provided the contractors with about 98,000 accounts representing $911 million in delinquent taxes.


upcoming event

Solution Seminar: Realizing the Benefits of Unified Physical and Logical Security Systems
May 6, 2008

Green Computing Summit 2008
May 20, 2008


 

head
fcw
issue
First Name State
Last Name Zip
Title Email