Section 9.3 of IRS Publication 1075 establishes the technical and procedural security controls + by inheritance from NIST SP 800-53 Rev 5 Security and Privacy Controls for Information Systems and Organizations. IRS Pub 1075 does NOT define its own control set + instead it INCORPORATES NIST SP 800-53 controls BY REFERENCE + with specific implementation guidance + IRS-specific FTI considerations + and tailored enhancements (often called IRS Moderate-Plus baseline - more rigorous than NIST 800-53 Moderate baseline + less rigorous than High baseline + with specific control enhancements for FTI confidentiality). 18 Control Families per NIST 800-53 + Section 9.3.x mapping: (9.3.1) Access Control AC + Section 9.3.1.1-17; (9.3.2) Awareness and Training AT + Section 9.3.2.1-4; (9.3.3) Audit and Accountability AU + Section 9.3.3.1-11; (9.3.4) Assessment + Authorization + Monitoring CA + Section 9.3.4.1-8; (9.3.5) Configuration Management CM + Section 9.3.5.1-11; (9.3.6) Contingency Planning CP + Section 9.3.6.1-11; (9.3.7) Identification and Authentication IA + Section 9.3.7.1-11; (9.3.8) Incident Response IR + Section 9.3.8.1-9; (9.3.9) Maintenance MA + Section 9.3.9.1-6; (9.3.10) Media Protection MP + Section 9.3.10.1-7; (9.3.11) Physical and Environmental Protection PE + Section 9.3.11.1-20; (9.3.12) Planning PL + Section 9.3.12.1-5; (9.3.13) Program Management PM + Section 9.3.13.1-16; (9.3.14) Personnel Security PS + Section 9.3.14.1-7; (9.3.15) Personally Identifiable Information Processing and Transparency PT + Section 9.3.15.1-5; (9.3.16) Risk Assessment RA + Section 9.3.16.1-7; (9.3.17) System and Services Acquisition SA + Section 9.3.17.1-22; (9.3.18) System and Communications Protection SC + Section 9.3.18.1-45; (9.3.19) System and Information Integrity SI + Section 9.3.19.1-17; (9.3.20) Supply Chain Risk Management SR + Section 9.3.20.1-11. FIPS 199 Categorisation: Confidentiality = HIGH for FTI (mandated by IRS); Integrity and Availability are typically Moderate but may be set higher by agency based on risk assessment. FIPS 200 Minimum Security Requirements: addressing all 18 families. NIST SP 800-37 Rev 2 Risk Management Framework (RMF) integration: Categorize + Select + Implement + Assess + Authorize + Monitor. NIST SP 800-53A Assessment Methodology + NIST SP 800-53B Control Baselines (Low/Moderate/High - IRS specifies its own profile). IRS Office of Safeguards conducts on-site reviews + may require Plan of Action and Milestones (POA&M) for findings + Corrective Action Plan (CAP) for systemic issues. Coordinates with NIST SP 800-53 Rev 5 + NIST SP 800-53A + NIST SP 800-53B + NIST SP 800-37 Rev 2 RMF + NIST SP 800-30 Risk Assessment + NIST SP 800-18 Security Plan + NIST SP 800-160 + FIPS 199 + FIPS 200 + FedRAMP Moderate/High + DoD CMMC + CJIS + CMS ARS. IRS Pub 1075 Section 9.3 + NIST 800-53 Inheritance applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.