PGLD/Incident Management Risk Assessment and Mitigation
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
PGLD/IM assesses the risk of harm to individuals potentially impacted by IRS data breaches involving the loss, theft, or inadvertent unauthorized disclosure of SBU data, including PII and tax information. When assessing the risk of harm to individuals potentially impacted by a data breach, the potential harms that could result from the loss or compromise of PII must be considered. Such harms may include the effect of a breach of confidentiality or fiduciary responsibility, the potential for blackmail, the disclosure of private facts, mental pain and emotional distress, financial harm, the disclosure of contact information for victims of abuse, the potential for secondary uses of the information which could result in fear or uncertainty, or the unwarranted exposure leading to humiliation or loss of self-esteem. Additionally, the Privacy Act requires the IRS to protect against any anticipated threats or hazards to the security or integrity of records which could result in substantial harm, embarrassment, inconvenience, or unfairness to any individual on whom information is maintained. The IRS must consider any and all risks relevant to the data breach, which may include risks to the IRS, IRS information systems, IRS programs and operations, other Treasury Bureaus, the Federal Government, or national security. These additional risks may properly influence the IRS’ overall response to a data breach and the steps the IRS must take to notify individuals. Note that all data breaches are unique and when making risk assessment determinations, all facts and circumstances must be considered.
Get a plain-English answer with a citation back to this text.
Ask AI about this code