Incident response for FTI breaches requires specific procedures beyond NIST 800-53 IR family. Reporting Timelines: (1) Within 24 hours of incident discovery (suspected or actual unauthorised disclosure inspection use or access of FTI) report to (a) IRS Office of Safeguards (via Office of Safeguards Incident Reporting Portal or email safeguardreports@irs.gov); (b) Treasury Inspector General for Tax Administration (TIGTA) Hotline at 1-800-589-3718 + by phone for urgent matters + by web form for less urgent; (c) Agency Inspector General if separate; (d) State + Local law enforcement if criminal activity suspected; (e) FBI if cyber incident; (f) US-CERT/CISA if federal reporting requirement applies; (g) Affected taxpayers if statutorily required (IRC 6103 disclosure). (2) Initial Notification Content: (a) Date + time of discovery + estimated date of incident; (b) Type of incident (theft + lost media + cyber breach + unauthorised disclosure + misdirected mail); (c) Description of FTI involved + categories + approximate volume; (d) Number of affected taxpayers; (e) Containment actions taken; (f) Initial remediation plan; (g) Point of contact. (3) Follow-up Reporting: SAR within 30 days + comprehensive incident report with full investigation + root cause analysis + corrective actions + impact assessment + lessons learned. (4) Incident Categories per IRS Pub 1075: (a) Lost or Stolen FTI (paper or electronic); (b) Misdirected/Misrouted FTI (incorrect recipient); (c) Unauthorised Access or Inspection by employee/contractor; (d) Unauthorised Disclosure to non-authorised party; (e) Cyber incident (malware + ransomware + phishing + DDoS); (f) Cloud/CSP incident affecting FTI; (g) Insider threat. (5) Investigation: cooperation with TIGTA + Office of Safeguards + law enforcement + forensic readiness + chain of custody + employee discipline + contractor termination as appropriate + criminal referral per IRC 7213/7213A. (6) Containment + Eradication + Recovery: standard incident response phases + plus FTI-specific actions including (a) immediate revocation of access for suspected insider; (b) isolation of compromised systems holding FTI; (c) wipe/destruction of unauthorised FTI copies; (d) password resets + credential rotation; (e) third-party forensic investigation for major incidents; (f) IRS-approved remediation. (7) Taxpayer Notification: typically by IRS rather than agency + per IRC 6103 disclosure standards + risk-based + identity theft monitoring + credit monitoring as appropriate. Coordinates with NIST SP 800-53 IR family + NIST SP 800-61 Computer Security Incident Handling Guide + NIST SP 800-34 Contingency Planning + TIGTA Hotline procedures + Office of Safeguards Incident Reporting + US-CERT/CISA + FBI Cyber Division + state law enforcement + IRC 6103 + 7213 + 7213A + 7431. IRS Pub 1075 Incident Response applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.