The IRS Office of Safeguards conducts continuous oversight of FTI safeguarding through structured reports + on-site reviews + assessments. (1) Safeguard Security Report (SSR) per Exhibit 3 + Section 9.6: comprehensive annual report submitted by all agencies receiving FTI + covering (a) Agency profile + FTI handling; (b) System security including FIPS 199 categorisation + NIST 800-53 controls implementation; (c) Personnel safeguards including background checks + NDA + training; (d) Physical safeguards; (e) Disposal procedures; (f) FTI inventory + system inventory; (g) Test of Controls + Compliance status; (h) POA&M for outstanding issues. SSR is the primary annual compliance document + must be approved by agency Chief Information Officer (CIO) or designee + maintained for 5 years. (2) Safeguard Activity Report (SAR) per Exhibit 5 + Section 9.7: incident-based or change-of-status report submitted within: 30 days for major changes (new contractor + new system + new FTI source + cloud migration + major staff change + security incident) + 24 hours for security incidents involving suspected or actual unauthorised disclosure. SAR triggers: (a) addition of new contractor or subcontractor with FTI access; (b) significant system architecture change; (c) move to cloud service; (d) personnel change (CIO + safeguards point of contact); (e) suspected or actual incident affecting FTI; (f) compliance issue identified. (3) On-Site Safeguard Review: Office of Safeguards conducts on-site review of each agency typically every 3 years + with focus on high-risk agencies more frequently + review includes (a) interview key personnel; (b) review documentation including SSR + SAR + POA&M + training records + access logs; (c) inspection of facilities + secure areas; (d) testing of controls; (e) random sampling of FTI handling procedures + records destruction observation; (f) cloud + contractor inspection. (4) Safeguard Computer Security Evaluation Matrix (SCSEM): standard checklists per technology platform + including SCSEM for Windows + Linux + Oracle + MS SQL Server + Sybase + Network Devices + Mobile + Cloud + Web Applications + Mainframe + Identity Management + databases - used by agencies for self-assessment + by Office of Safeguards for on-site reviews. Available on IRS Safeguards portal. (5) Plan of Action and Milestones (POA&M): formal record of weaknesses + planned corrective actions + responsible parties + due dates + status tracking per NIST SP 800-37 RMF + IRS-required for any open finding. (6) Corrective Action Plan (CAP): for systemic findings + may include suspension of FTI access pending remediation. (7) IRS Pub 4761 Safeguard Procedures Report (SPR): a separate report covering procedures only (not full SSR scope) used for certain federal agency relationships. (8) IRS Pub 4812 Contractor Security Controls: companion publication for contractors. (9) Notification of Disclosure (NOD): record kept by agency for every disclosure of FTI per IRC 6103. Coordinates with FISMA + OMB A-130 + NIST SP 800-37 RMF + NIST SP 800-53A Assessment + IRS Office of Safeguards portal + State revenue agencies + cloud service providers + contractors. IRS Office of Safeguards Reviews applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.