Internal Revenue Service (IRS) Publication 1075 Tax Information Security Guidelines for Federal + State and Local Agencies + Safeguards for Protecting Federal Tax Returns and Return Information. Most recent revision: Rev. November 2021 (preceded by Rev. October 2014). Authority basis: Internal Revenue Code (IRC) 26 USC 6103 + specifically IRC 6103(p)(4) which establishes the requirement for safeguard procedures + permitted disclosure conditions + and authorisation framework + plus IRC 6103(j) + (l) + (m) + (n) + (o) for specific information-sharing arrangements with state revenue agencies + federal agencies (SSA + Social Security Administration + ED + Department of Education + DOL + Department of Labor + HHS + Department of Health and Human Services + state child support enforcement + state employment security agencies + state and local tax administration agencies). Federal Tax Information (FTI) Definition per IRC 6103(b)(2): returns and return information + including any data + statement + tape + transcript + program or other matter produced or imported from the IRS + or that has been derived from the IRS + as well as books + records + or other tangible items relating to the IRS source data. Office of Safeguards Mission: promote taxpayer confidence in the integrity of the tax system by ensuring the confidentiality of IRS information provided to federal + state + and local agencies. Office of Safeguards Vision: serve as a trusted advisor to Partners + ensuring they have full understanding and insight into FTI requirements and their risk profile + obtaining consistent and timely guidance from a single voice. Applicability: applies to (a) Federal agencies + (b) State and Local agencies + (c) Contractors + (d) Subcontractors + (e) Cloud Service Providers (CSPs) + (f) Telecommunications providers + (g) Off-shore facilities (PROHIBITED for FTI - see Exhibit 4 + Section 9.4) - that receive + process + store + transmit + or otherwise handle FTI. Coordinates with: NIST SP 800-53 Rev 5 (incorporated by reference + see Section 9.3 mapping below) + FIPS 199 (Confidentiality = HIGH for FTI) + FIPS 200 (minimum security requirements) + FISMA (Federal Information Security Modernization Act of 2014 + previously 2002) + Office of Management and Budget (OMB) Circular A-130 + FedRAMP (Federal Risk and Authorization Management Program) + Federal Information Security Risk Management Framework (RMF) + 26 USC 6103 + 26 USC 7213 (criminal penalties for unauthorised disclosure) + 26 USC 7213A (unauthorised inspection penalties) + 26 USC 7431 (civil damages for unauthorised disclosure) + Privacy Act of 1974 (5 USC 552a) + Tax Information Authorization (TIA) Form 8821 + Power of Attorney (POA) Form 2848 + IRS Pub 4812 Contractor Security Controls + IRS Pub 4761 Safeguard Procedures Report + FBI CJIS Security Policy (for criminal justice information) + SSA CDS (Computer Data Security Procedures Manual) + state tax administration agencies. IRS Pub 1075 Scope + IRC 6103 + FTI + Office of Safeguards applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.