Ads by TechWords

See your link here
Receive the latest technology news and information.
Mobile/Wireless Computing
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

IRS still losing laptops

More security needed, audit says

April 5, 2007 12:00 PM ET

InfoWorld - A new report filed by federal security auditors finds that that the U.S. Internal Revenue Service has had almost 500 laptop computers lost or stolen over the last three years, many of which were loaded with sensitive taxpayer information.

In a memo authored by the Treasury Department's Inspector General for Audit, Michael R. Phillips, investigators maintain that the IRS is not adequately protecting taxpayer data on laptops and other portable electronic media devices. The report contends that between 2003 and 2006 the IRS had some 490 laptops lost or stolen in 387 individual incidents.

In the missive, originally filed to IRS leaders on March 23, the auditors said 176 of those incidents did not involve the potential exposure of taxpayer data, but noted that the information of at least 2,300 individuals was stored on the other missing laptops.

The investigators said that they were unable to deduce whether taxpayer information was exposed via 85 of the reported device losses, however, it was confirmed that the personal information of at least 3,359 taxpayers was misplaced in the other incidents.

While chilling, the report does in fact show signs that the IRS has slowed the loss of computing devices over the last few years. In Jan. 2002, the IRS admitted in a similar audit that it had lost or misplaced some 2,332 laptops, desktops and servers over the previous 36 months.

According to the report, a large number of the missing laptops were stolen from employees' vehicles and residences, with an additional 111 of the incidents occurring within IRS facilities.

Perhaps the most notorious loss of a laptop in the federal sector came in May 2006 when a contractor working with the Department of Veterans Affairs had a computer stolen from his home that carried the personal data of an estimated 26.5 million people. The laptop was eventually recovered by law enforcement officials.
In addition to failing to properly secure their devices in and out of the office, the auditors said that some of the IRS' 100,000 employees were not properly encrypting data on their machines or utilizing adequate password protections.

Further, the auditors said that they conducted a test on 100 laptop computers currently in use by IRS employees and determined that 44 of the devices contained unencrypted sensitive data, including taxpayer data and employee personnel data.

The IRS requires usernames and passwords on its laptops, but 15 of the 44 computers with unencrypted sensitive data also contained security vulnerabilities that could allow for circumvention of those tools.

"As a result, we believe it is very likely a large number of the lost or stolen IRS computers contained similar unencrypted data," the inspectors wrote in the report. "Employees did not follow encryption procedures because they were either unaware of security requirements, did so for their own convenience, or did not know their own personal data were considered sensitive."


Reprinted with permission from

For more enterprise computing news, visit Infoworld.com
Story copyright 2006 InfoWorld Media Group, Inc. All rights reserved.

Jump to comments

IRS

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Accelerating Your Mobile Workers: Controlling the Uncontrollable
Today's workforce is truly mobile. Unlike the managed environment of the office LAN, remote users face many challenges to being productive while out...

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Managing Laptops Outside the Office
Learn how you can reduce costs by tracking mobile computers no matter where they are located.

Mobile U Webinar
Watch Now!

The New Mobile Order
Download Now  

4G Ahead Video Program
Uncover the features and benefits of the two leading 4G technologies for enterprises considering future deployment.

WAN Application Delivery for Executives
Learn how to simplify server and application administration without creating performance problems for distributed users.  

Horror stories: Managing IT Across Multiple Locations
How one extra sharp IT manager eliminates daily agony, hassle and repetition.


IT Jobs