IRS Publication 1075
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
IRS Pub 1075 Coordination
Coordination positions IRS Pub 1075 within the broader US federal + state + and industry security landscape. (1) NIST Standards: NIST SP 800-53 Rev 5 (primary control set incorporated by reference Section 9.3) + NIST SP 800-53A (assessment methodology) + NIST SP 800-53B (control baselines) + NIST SP 800-37 Rev 2 Risk Management Framework (RMF) + NIST SP 800-30 Risk Assessment + NIST SP 800-18 Security Plan + NIST SP 800-60 Mapping Information Types to Security Categories + NIST SP 800-88 Media Sanitization + NIST SP 800-122 PII + NIST SP 800-171 CUI + NIST SP 800-145 Cloud Computing Definition + FIPS 199 Categorisation + FIPS 200 Minimum Security Requirements + FIPS 140-3 Cryptographic Modules + FIPS 201 PIV + NIST Cybersecurity Framework (CSF) v2.0. (2) Federal Information Security: FISMA Federal Information Security Modernization Act 2014 (and 2002 predecessor) + OMB Circular A-130 Man
- NIST standards + 800-53/-37/-30/-88/-122/-145 + FIPS integrated + records + audit
- FISMA + OMB + CISA + federal information security + records + reporting
- FedRAMP + ConMon + 3PAO + records + cloud authorization
- Sister programs + CJIS + SSA CDS + CMS ARS + state coordination + records
- Industry frameworks + SOC 2 + ISO 27001 + CIS + NIST CSF + records + cross-mapping
- NIST 800-53 implemented in isolation (no Pub 1075 tailoring)
- FISMA compliance pro forma (no OMB or CISA integration)
- FedRAMP not coordinated with IRS-specific requirements
- Sister programs not engaged (CJIS or SSA CDS overlap unaddressed)
- Industry frameworks fragmented (SOC 2 + ISO 27001 + Pub 1075 in silos)
IRS Pub 1075 Incident Response
Incident response for FTI breaches requires specific procedures beyond NIST 800-53 IR family. Reporting Timelines: (1) Within 24 hours of incident discovery (suspected or actual unauthorised disclosure inspection use or access of FTI) report to (a) IRS Office of Safeguards (via Office of Safeguards Incident Reporting Portal or email safeguardreports@irs.gov); (b) Treasury Inspector General for Tax Administration (TIGTA) Hotline at 1-800-589-3718 + by phone for urgent matters + by web form for less urgent; (c) Agency Inspector General if separate; (d) State + Local law enforcement if criminal activity suspected; (e) FBI if cyber incident; (f) US-CERT/CISA if federal reporting requirement applies; (g) Affected taxpayers if statutorily required (IRC 6103 disclosure). (2) Initial Notification Content: (a) Date + time of discovery + estimated date of incident; (b) Type of incident (theft + lo
- 24-hour notification capability + TIGTA + Office of Safeguards contact + records + drills
- Initial notification templates + required elements + records + per category
- SAR follow-up + 30-day + comprehensive investigation + root cause + lessons + records
- Containment + eradication + recovery procedures + forensic readiness + records
- Coordination + law enforcement + TIGTA + internal + records + discipline
- 24-hour notification missed (treated as ordinary cyber incident)
- Notification content incomplete (no FTI volume or taxpayer count)
- SAR follow-up absent (only 24h notification, no comprehensive report)
- Containment uncoordinated (no forensic readiness)
- Discipline not pursued (employee responsibility not addressed)
IRS Pub 1075 Office of Safeguards Reviews
The IRS Office of Safeguards conducts continuous oversight of FTI safeguarding through structured reports + on-site reviews + assessments. (1) Safeguard Security Report (SSR) per Exhibit 3 + Section 9.6: comprehensive annual report submitted by all agencies receiving FTI + covering (a) Agency profile + FTI handling; (b) System security including FIPS 199 categorisation + NIST 800-53 controls implementation; (c) Personnel safeguards including background checks + NDA + training; (d) Physical safeguards; (e) Disposal procedures; (f) FTI inventory + system inventory; (g) Test of Controls + Compliance status; (h) POA&M for outstanding issues. SSR is the primary annual compliance document + must be approved by agency Chief Information Officer (CIO) or designee + maintained for 5 years. (2) Safeguard Activity Report (SAR) per Exhibit 5 + Section 9.7: incident-based or change-of-status report su
- SSR annual + CIO-approved + comprehensive + 5-year retention + Office of Safeguards submission
- SAR + 30-day changes + 24-hour incidents + records + Office of Safeguards
- On-site review readiness + documentation + records + interview prep + inspection
- SCSEM self-assessment + per technology platform + records + remediation
- POA&M + CAP + corrective action + tracking + records + Office of Safeguards reporting
- SSR not annually submitted (or pro forma without CIO approval)
- SAR not submitted within 24h for incidents (or 30 days for changes)
- On-site review unready (no records or documentation available)
- SCSEM self-assessment not done (gaps identified only by Office of Safeguards)
- POA&M absent or stale (no tracking of corrective actions)
IRS Pub 1075 Personnel Security
Personnel Security per Section 9.3.14 PS family + IRS-specific enhancements + Exhibit 6 ensure that all individuals with FTI access are trustworthy and accountable. (1) Background Investigations: per OPM Federal Investigative Standards + tiered investigations - (a) Tier 1 (Public Trust low risk) for occasional FTI access; (b) Tier 2 (Public Trust moderate risk + Childcare Worker) for routine FTI access; (c) Tier 3 (Confidential clearance equivalent) for sensitive FTI work or contractor staff; (d) Tier 5 (Secret/Top Secret) for national security related; periodic reinvestigation every 5 years (Tier 5) + 10 years (Tier 3 + Tier 2) + ad-hoc on incident. Background check elements: identity verification + criminal records + credit check + employment history + reference check + residence verification + foreign contacts disclosure + medical/psychological as required. (2) Non-Disclosure Agreemen
- Background investigation + tier + records + reinvestigation + 5/10 year + records
- NDA Exhibit 6 + signed + initial + annual + records + audit
- Disclosure awareness training + annual + role-based + records + certification
- US citizen/Green Card + foreign national approval + records + verification
- Disciplinary action + termination + immediate revocation + return of FTI + records
- Background investigation not tiered to FTI sensitivity
- NDA missing or pro forma (no Exhibit 6 specific language)
- Annual training skipped (only initial)
- US citizen requirement bypassed (foreign nationals without approval)
- Disciplinary action ad-hoc (no documented procedure)
IRS Pub 1075 Scope + IRC 6103 + Office of Safeguards
Internal Revenue Service (IRS) Publication 1075 Tax Information Security Guidelines for Federal + State and Local Agencies + Safeguards for Protecting Federal Tax Returns and Return Information. Most recent revision: Rev. November 2021 (preceded by Rev. October 2014). Authority basis: Internal Revenue Code (IRC) 26 USC 6103 + specifically IRC 6103(p)(4) which establishes the requirement for safeguard procedures + permitted disclosure conditions + and authorisation framework + plus IRC 6103(j) + (l) + (m) + (n) + (o) for specific information-sharing arrangements with state revenue agencies + federal agencies (SSA + Social Security Administration + ED + Department of Education + DOL + Department of Labor + HHS + Department of Health and Human Services + state child support enforcement + state employment security agencies + state and local tax administration agencies). Federal Tax Informati
- FTI inventory + sources per 6103 + data flow + records + audit
- Office of Safeguards engagement + records + authorisation + relationship
- Federal/State/Local + Contractor + Subcontractor classification + records
- Offshore prohibition + geographic boundary + cloud region + records
- Penalty awareness + 7213 imprisonment + 7213A inspection + 7431 civil + Board records
- FTI inventory absent (data flow not mapped)
- No Office of Safeguards engagement (no SAR or SSR submitted)
- Contractor/subcontractor classification missing
- Offshore access not prohibited (cloud in non-US region)
- Penalty exposure not Board-level (criminal/civil)
IRS Pub 1075 Section 9.1-9.2 FTI Specific
Sections 9.1-9.2 of IRS Publication 1075 establish FTI-specific requirements that are NOT covered by NIST SP 800-53 but are specific to the IRS FTI protection regime. Section 9.1 Recordkeeping Requirements: maintain detailed records of FTI receipt + processing + disclosure + destruction + including (a) FTI Inventory + Custody Log + Receipt + Tracking; (b) Disclosure Accounting per 6103 + log of every authorised disclosure with date + recipient + purpose + statutory basis; (c) Audit Trail of all access to FTI systems + including Identifier + Timestamp + Action + Data Element; (d) Records retention per IRS Records Control Schedule (RCS) + minimum 5 years for FTI access logs + longer for safeguard records. Section 9.2 Disclosure Restrictions and Re-Disclosure: FTI may be disclosed ONLY in accordance with IRC 6103 + including (a) only to authorised personnel with bona fide need to know; (b)
- FTI inventory + custody log + disclosure accounting + audit trail + records + 5-year retention
- Disclosure restrictions + authorised personnel + need-to-know + 6103 basis + records
- FTI transmission encryption + FIPS 140-3 + TLS 1.2+ + SFTP + S/MIME + records
- Document control + print + inventory + cross-cut shred + NIST 800-88 destruction + records
- NDA signed + disclosure training + Exhibit 7 contract language + subcontractor + records
- FTI custody log absent or incomplete (no chain of custody)
- Disclosure accounting not maintained (cannot prove 6103 basis)
- Transmission using non-validated cryptography or plain FTP
- Document destruction not NIST 800-88 compliant (e.g. strip shredders)
- Contract language missing Exhibit 7 mandatory provisions
IRS Pub 1075 Section 9.3 NIST 800-53 Inheritance
Section 9.3 of IRS Publication 1075 establishes the technical and procedural security controls + by inheritance from NIST SP 800-53 Rev 5 Security and Privacy Controls for Information Systems and Organizations. IRS Pub 1075 does NOT define its own control set + instead it INCORPORATES NIST SP 800-53 controls BY REFERENCE + with specific implementation guidance + IRS-specific FTI considerations + and tailored enhancements (often called IRS Moderate-Plus baseline - more rigorous than NIST 800-53 Moderate baseline + less rigorous than High baseline + with specific control enhancements for FTI confidentiality). 18 Control Families per NIST 800-53 + Section 9.3.x mapping: (9.3.1) Access Control AC + Section 9.3.1.1-17; (9.3.2) Awareness and Training AT + Section 9.3.2.1-4; (9.3.3) Audit and Accountability AU + Section 9.3.3.1-11; (9.3.4) Assessment + Authorization + Monitoring CA + Section 9.
- NIST SP 800-53 Rev 5 + 18 families + IRS tailoring + Pub 1075 Section 9.3 mapping + records
- FIPS 199 categorisation + HIGH confidentiality for FTI + I/A levels + records
- Section 9.3.x implementation + per family + IRS enhancements + records
- POA&M + findings + remediation + tracking + records + Office of Safeguards reporting
- RMF + authorization boundary + ATO + continuous monitoring + records
- NIST 800-53 adopted but no Pub 1075 Section 9.3 specific tailoring
- FIPS 199 default rating (not HIGH for confidentiality despite FTI)
- Section 9.3.x implementation incomplete (some families not addressed)
- POA&M not maintained (findings unaddressed)
- RMF authorization stale or not specific to FTI scope
IRS Pub 1075 Section 9.4 Cloud + Offshore
Section 9.4 of IRS Publication 1075 establishes specific requirements for cloud services and addresses the prohibition on offshore processing of FTI. (1) FedRAMP Authorisation: cloud service providers (CSPs) handling FTI must be FedRAMP Moderate or High Baseline authorised + plus IRS-specific tailoring per IRS Office of Safeguards Cloud Computing Notification (CCN). Acceptable CSPs (as of 2026): AWS GovCloud (US) + Azure Government + Azure Government Secret + Oracle US Federal Cloud + Google Workspace for Government + IBM Federal Cloud + Salesforce Government Cloud + others FedRAMP-authorised. (2) Cloud Computing Notification (CCN): agencies migrating FTI to cloud must submit CCN to Office of Safeguards prior to deployment + SAR follow-up within 30 days. (3) Offshore Prohibition (Exhibit 4): FTI processing PROHIBITED outside the United States + including Puerto Rico + Guam + Virgin Islan
- FedRAMP authorised CSP + ATO + Moderate/High + IRS tailoring + records
- CCN + SAR + Office of Safeguards approval + records
- Offshore prohibition + US-region + US citizen + records + verification
- CSP contract + audit rights + incident notification + destruction NIST 800-88 + records
- Continuous monitoring + SOC 2 Type II + ISO 27001 + FedRAMP ConMon + records
- Non-FedRAMP CSP used for FTI (compliance violation)
- CCN not submitted before cloud migration
- Offshore access permitted (cloud region or personnel)
- CSP contract missing audit rights or destruction provisions
- Continuous monitoring absent (point-in-time only)
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.