Note:
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
Sections in this part
A third-party data owner is defined as a data owner external to the IRS. An external third-party data breach is an event that results from the unauthorized use or loss of SBU data (including PII and tax information) that does not involve IRS systems, applications, or online services. Third-party data breaches can be reported to the IRS by external sources, such as practitioners, software developers, state and local agencies, or others.
BU data owners will:
Notify PGLD and IRS senior management as needed.
Take immediate action to contain potential data leakage and mitigate risk, such as engaging Cybersecurity’s Online Fraud Detection and Prevention (OFDP) Office to deactivate a fraudulent website; recovering hardcopy documents; or coordinating with TIGTA to ensure all recovery options are considered.
PGLD will:
Identify members needed for a Breach Response Team (BRT) or Working Group (WG).
Notify the Department of the Treasury as applicable.
A Breach Response Team (BRT) will be convened for high-risk data breaches and for any data breach that constitutes a major incident (as defined in OMB guidance) to address the additional concerns and communication issues that may be involved with these types of data breaches. The purpose of the BRT is to provide a swift, effective and orderly response to these types of data breaches. The team is led by the Breach Coordinator (BC) and is composed of cross-functional representatives authorized to take the necessary steps to contain, mitigate or rectify a data breach, mitigate the vulnerability of taxpayer data, and rebuild trust. Participating members of the BRT can vary based on the nature and scope of the data breach and the potential risk to taxpayers.
A Working Group (WG) is comprised of members from several different components of a BRT to address the specifics of an investigation prior to the formation of a full BRT. WGs are commonly formed for investigations into suspicious behavior on IRS systems and applications.
PGLD/IM reports high-risk data breaches to the Facilities Management and Security Services (FMSS) Threat and Incident Response Center (TIRC). The TIRC is comprised of staff from FMSS, the Treasury Inspector General for Tax Administration-Criminal Intelligence and Counterterrorism Group (TIGTA-CICT), Criminal Investigation (CI), Federal Protective Service (FPS), the Computer Security Incident Response Center (CSIRC), and the Office of Privacy, Governmental Liaison and Disclosure (PGLD), including the Records and Information Management (RIM) Program Office. The mission of the TIRC is to identify and mitigate threats and record countermeasures and mitigation strategies as it pertains to Federal tax administration and the IRS for the protection of service operations. Reporting to SAMC may also be required if the reporting does not lead to SAMC Leadership messaging and communication is warranted based on the circumstances of the event.
See the following resources regarding high-risk data breaches. Both are listed in the Other Related Resources section of the Report Losses, Thefts or Disclosures page in the Disclosure and Privacy Knowledge Base Site.
The High-Risk Data Breach Quick Reference Guide contains the high-level process to follow when a high-risk data breach is identified.
Document 13347, Data Breach Response Playbook, contains detailed procedures on the proper steps to take if your area has a high-risk data breach to help you minimize harm to taxpayers, document the data breach, and manage the risk assessment process.
Get a plain-English answer with a citation back to this text.
Ask AI about this code