Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

11/17/2011
09:35 AM
50%
50%

GAO Rips IRS Taxpayer Data Security

Auditors find holes in the federal revenue agency's database access control and security.

A new report from the Government Accountability Office (GAO) ripped into the IRS once again for insufficient access controls, database maintenance, and monitoring necessary to keep taxpayer information safe. The report's findings echo many of the issues seen in database and application security across many large enterprises today, experts say. Released last week, the GAO's financial audit (PDF) reported that during the past fiscal year, the IRS still had glaring holes in internal controls over information security, in spite of initiating efforts to address concerns levied by the GAO in past years.

"IRS improved several system-level controls, including the encryption of data transferred between some accounting systems, upgrades to critical network devices on the agency's internal network, and strengthening of the architecture of an important financial system to eliminate identified areas of weakness," the report read. "However, despite these efforts and enhanced management attention toward controls, a majority of the known weaknesses in the agency's systems and internal network and physical security controls remained unresolved in fiscal year 2011."

According to Don Gray, chief security strategist for Solutionary, an Omaha-based managed security service provider, the IRS isn't special in the fact that it hasn't been able to keep up with regulator demands.

"They've partially addressed the findings that were found before, and they've somewhat implemented some controls. Quite frankly, we see that a lot in large organizations," he says. "For instance, the IRS has this system it was supposed to put in place to collect and analyze user activity. They've got it in a couple of applications, but they don't have it in all the key financial applications. That is something we see time and time again at the corporate level."

Gray says he often sees organizations incorporate monitoring, for instance, on network devices and platforms, but then fail to monitor applications and databases.

"On network devices and platforms, that's easy. Everybody can do it on a Cisco device or a Windows OS," he says. "It's when you actually get down to wanting to tailor that and give yourself visibility on the applications and database side that it gets hard."

Read the rest of this article on Dark Reading.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Data Leak Week: Billions of Sensitive Files Exposed Online
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
Intel Issues Fix for 'Plundervolt' SGX Flaw
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19794
PUBLISHED: 2019-12-13
The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.
CVE-2019-19795
PUBLISHED: 2019-12-13
samurai 0.7 has a heap-based buffer overflow in canonpath in util.c via a crafted build file.
CVE-2019-19796
PUBLISHED: 2019-12-13
Yabasic 2.86.2 has a heap-based buffer overflow in myformat in function.c via a crafted BASIC source file.
CVE-2019-5253
PUBLISHED: 2019-12-13
E5572-855 with versions earlier than 8.0.1.3(H335SP1C233) has an improper authentication vulnerability. The device does not perform a sufficient authentication when doing certain operations, successful exploit could allow an attacker to cause the device to reboot after launch a man in the middle att...
CVE-2019-5260
PUBLISHED: 2019-12-13
Huawei smartphones HUAWEI Y9 2019 and Honor View 20 have a denial of service vulnerability. Due to insufficient input validation of specific value when parsing the messages, an attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices to exploit this vul...