Glossary of Incident Management Terms, Definitions, and Acronyms
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
TERM
DEFINITION
Access
The authority granted to employees and contractors that provide opportunity to physically come into contact with (including, but not limited to reading, transporting, and/or transcribing/interpreting) sensitive but unclassified (SBU) data in the performance of official duties; entering an IRS facility without escort; and/or to login to IRS systems with approved credentials.
Accounts Management (AM) Customer Service Representatives (CSRs)
AM CSRs assist individuals impacted by IRS data breaches by answering general data breach related inquiries or preparing a Form 4442, Inquiry Referral, if the caller requests specific information about the data breach that the AM CSR is unable to answer. AM CSRs also provide assistance to individuals impacted by identity theft or individuals who could become victims of identity theft in the future due to a data loss such as a lost or stolen purse/wallet, questionable credit card activity, etc. This assistance is provided by AM CSRs even if the individual has not experienced any problems with, or received communications from, the IRS.
Audience
The employees responsible for taking action or who require knowledge about the program, process or activity.
Breach Response Team (BRT)
The BRT is the group of individuals that will respond to a high-risk data breach or any data breach that constitutes a major incident as defined in OMB guidance. See Document 13347, Data Breach Response Playbook, for additional information about the BRT.
Bring Your Own Device (BYOD)
Bring Your Own Device is a concept that allows employees to use their personally owned technology devices to stay connected to, access data from, or complete tasks for their organizations. At a minimum, BYOD programs allow users to access employer-provided services and/or data on their personal tablets/eReaders, smartphones, and other devices.
Business Unit (BU) Data Owner
The BU who has responsibility for the data/information and is therefore responsible for containment and mitigation of the data breach, e.g., if a Power of Attorney (POA) tells an SBSE revenue officer (RO) he or she received IVES transcripts he or she did not request, the reporting employee/point of contact (POC) is the RO, but TS is the data owner and carries the responsibility for mitigation and containment. Note that Data Owner is synonymous with Information Owner. Per IRM 10.8.2.2.1.6, Information Owner, "The Information Owner is an IRS official with statutory or operational authority for specified information and responsibility for establishing the controls for its generation, collection, processing, dissemination, and disposal. At the IRS, the Information Owner is the Business and Functional Unit Owner."
Classified Waste
Classified waste is documentation containing taxpayer entity or account information that is not part of the case and is not needed for audit trail purposes. Refer to IRM 21.5.1, Account Resolution - General Adjustments, for guidance on handling classified waste to prevent inadvertent/unauthorized destruction of records.
Cybersecurity and Infrastructure Security Agency (CISA) (formerly US-CERT)
CISA retired US-CERT and ICS-CERT on February 24, 2023. CISA is responsible for coordinating cybersecurity programs within the U.S. government to protect against malicious cyber activity, including activity related to industrial control systems.
Cybersecurity Information Protection Enhancement Controls (CIPEC)
A Data Loss Prevention (DLP) tool within the IRS Cybersecurity toolkit. DLP is technology that scans unencrypted, outbound transmissions to advance data protection and reduce inadvertent disclosures.
Computer Security Incident Response Center (CSIRC)
Responsible for monitoring the IRS network 24 hours a day year-round for cyberattacks and computer vulnerabilities and for various security incidents such as the theft of a laptop computer.
Data Breach
OMB M-17-12 defines a data breach as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person, other than an authorized user accesses or potentially accesses personally identifiable information, or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.
Get a plain-English answer with a citation back to this text.
Ask AI about this code