SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Nearly 500 laptops stolen from IRS, audit says

Nearly 500 laptops stolen from IRS, audit says

By:  Linda Rosencrance  On: 08 Apr 2007 For: Computerworld (US online) Creator

Over the past three years, 490 laptops were lost or stolen from the Internal Revenue Service, according to an audit by the Treasury Inspector General for Tax Administration. Between Jan. 2, 2003 and June 13, 2006, a "large number" of the laptops were stolen from the vehicles and homes of IRS employees, according to the report released last month, while 111 were stolen from IRS facilities, the report said.

COMMENT ON THIS ARTICLE

Over the past three years, 490 laptops were lost or stolen from the Internal Revenue Service, according to an audit by the Treasury Inspector General for Tax Administration. Between Jan. 2, 2003 and June 13, 2006, a "large number" of the laptops were stolen from the vehicles and homes of IRS employees, according to the report released last month, while 111 were stolen from IRS facilities, the report said.

Although auditors were unable to determine what taxpayer information was contained on the missing laptops, they said employees are not adequately protecting taxpayers' personal information contained on IRS laptops.

"We conducted a separate test on 100 laptop computers currently in use by employees and determined 44 laptop computers contained unencrypted sensitive data, including taxpayer data and employee personnel data," the report said. "As a result, we believe it is very likely a large number of the lost or stolen IRS computers contained similar unencrypted data." Auditors said IRS employees did not follow the department's encryptions procedures because they were unaware of security requirements, did so for their own convenience or did not know the personal data was considered sensitive.

"We also found other computer devices, such as flash drives, CDs, and DVDs, on which sensitive data were not always encrypted," according to the report. "We reported similar findings in July 2003, but the IRS had not taken adequate corrective actions."

Although the IRS also requires employees to restrict access to their laptops with user names and passwords, 15 of the 44 laptops that contained unencrypted data also had security weaknesses that could be exploited to bypass these security controls, the auditors said. "We believe system administrators either incorrectly configured the computers upon deployment or did not correctly reset the controls after working on the computers," the auditors said. "We also evaluated the security of backup data stored at four offsite facilities. Backup data were not encrypted and adequately protected at the four sites."

In a written response to the report, Richard Spires, CIO of the IRS, said his agency was taking aggressive steps to mitigate the risk of potential identity theft or other fraudulent activity, including providing IRS employees with the capability to encrypt sensitive files and e-mails on their computers; deploying full disk encryption technology and physical cable locks on all employee laptops; and identifying a secure encryption alternative for tapes exchanged with federal, state and other partners.

COMMENT ON THIS ARTICLE


Sign up for our Newsletters












Print |  Views: 590   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Linda Rosencrance Linda Rosencrance is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Opinion: Cryptic Reading
Opinion: Cryptic ReadingA report released by the Government Accountability details lax encryption efforts at 24 U.S. agencies and departments.
FBI in the dark about its own lost laptops
FBI in the dark about its own lost laptopsThe FBI lost 160 laptop computers in less than four years - an average of nearly four each month - according to the inspector general for the Department of Justice. In many cases, the FBI didn't know what was on the missing computers. The inspector general criticized the agency for not enforcing its own rules on reporting lost or stolen hardware and hit the agency for not being able to detail the contents of the laptops.
Mobile defence forces
Mobile defence forcesPerhaps you followed the dramatic headlines in May as the U.S. Department of Veterans Affairs came to grips with the fact that it had lost a laptop (that has since been recovered) with personal information on 26.5 million veterans and active-duty soldiers, potentially exposing them to identity theft.
McAfee coming to an Intel laptop, MID near you
security vendor mcafee announced yesterday its plans to extend its products to intel-based laptops and mobile internet devices (mids).integrated data encryption and integrated mobile content security will be provided for laptops and mids using intel atom processor z5xx series and moblin-based software.intel's anti-theft technology and active management techn
blog comments powered by Disqus