Note:
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
See also the definition of "Data Breach."
Incident Management (IM)
Incident Management (IM) refers to the Office within PGLD responsible for the process of managing incidents involving a loss, theft, or inadvertent unauthorized disclosure of SBU data, including PII and tax information, by the IRS.
Incorrect Correspondence
A notice or letter (received traditionally or digitally) containing one or more of the following issues: misspellings or bad grammar; incorrect IRS phone numbers; incorrect QR codes or URL Links; incorrect, missing, or unreadable text; or incorrect account information.
Information Technology
Any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by an executive agency.
Loss
Any event where an item is misplaced and/or neither the official owner nor the intended recipient has possession of the item in the expected time frame. A loss may involve an IRS-owned physical asset such as a laptop, cell phone, and/or other portable media, or electronic or hard copy data that may contain sensitive but unclassified (SBU) data, including personally identifiable information (PII) and tax information, such as paper or electronic taxpayer records, personnel records, or other identifying data, or a combination of a physical asset and electronic and/or hard copy data. A loss involving PII is known as a Data Breach.
Major Incident
OMB M-25-04, Fiscal Year 2025 Guidance on Federal Information Security and Privacy Management Requirements, defines a major incident as any incident that is likely to result in demonstrable harm to the national security interests, foreign relations, or the economy of the United States, or to the public confidence, civil liberties, or public health and safety of the American people. A data breach (see the definition of "data breach" above) constitutes a major incident when it involves PII that, if exfiltrated, modified, deleted, or otherwise compromised, is likely to result in demonstrable harm to the national security interests, foreign relations, or the economy of the United States, or to the public confidence, civil liberties, or public health and safety of the American people. An unauthorized modification of, unauthorized deletion of, unauthorized exfiltration of, or unauthorized access to 100,000 or more individuals’ PII constitutes a major incident.
National Archives and Records Administration (NARA)
NARA is an independent agency of the U.S. Government charged with the preservation and documentation of government and historical records. NARA establishes policies and procedures for managing U.S. Government records and assists federal agencies in administering records management programs and related activities.
National Institute of Standards and Technology (NIST)
A non-regulatory federal agency within the U.S. Department of Commerce that develops and promotes measurement, standards, and technology.
The Office of Management and Budget (OMB)
OMB assists the President in overseeing the preparation of the Federal budget and evaluates the effectiveness of agency programs, policies, and procedures, and works to make sure that agency reports, rules, testimony, and proposed legislation are consistent with the President's Budget and with Administration policies. In addition, OMB oversees and coordinates the Administration's regulatory, procurement, financial management, information technology, and information management policies.
Personally Identifiable Information (PII)
The term PII refers to information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual. See OMB Circular No. A-130, and OMB M-17-12 and the PGLD webpage, Personally Identifiable Information for additional information.
Phishing
Phishing is a scam where Internet fraudsters send email messages to trick unsuspecting victims into revealing personal and financial information that can be used to steal the victim's identity. See IRM 21.1.3.23, Scams (Phishing) and Fraudulent Schemes.
PII Working Group (PIIWG)
A decision-making body consisting of senior management and technical experts from all key business and functional unit stakeholders with expertise in information technology, legal requirements, privacy, law enforcement and information security.
Policy Owner
The IRS organization or the title of the executive (position only) responsible for the program.
Potential Level of Risk: No Impact
The loss of confidentiality, integrity, or availability could be expected to have no adverse effect on organizational operations, organizational assets, or individuals.
Potential Level of Risk: Low Impact
The loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals.
Potential Level of Risk: Moderate Impact
The loss of confidentiality, integrity, or availability could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.
Potential Level of Risk: High Impact
The loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.
Potentially Impacted Individual
Individuals, as defined by the Privacy Act of 1974, potentially impacted by occurrences of IRS data losses, thefts, and inadvertent unauthorized disclosures involving SBU data, including PII and tax information, are known as “Potentially Impacted Individuals”. Consistent with OMB directives, the IRS notifies potentially impacted individuals when a data breach involves the loss, theft, or inadvertent unauthorized disclosure of PII, and the result of the risk assessment indicates there is a potential risk that the compromised data may be used by someone other than the owner of the information to commit a crime or fraud.
Program Owner
The office which has primary responsibility for establishing the policy, process, and procedures to implement and manage the IRS program. Directors within this office are responsible for developing and publishing IRM procedures. The program owner is the IRM owner for the program.
Records
Includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them. (44 USC 3301).
Records and Information Management
In keeping with the Federal Records Act of 1950, as amended, and pursuant to 44 USC 3102, the IRS established a records management program - renamed Records and Information Management (RIM) Program - to ensure the economical and efficient management of its records in the creation, maintenance, retrieval, preservation, and disposition of all records.
Reporting Employee/Point of Contact (POC)
The reporting employee/POC is the employee who identifies/recognizes a data breach and reports the data breach as required. The reporting employee/POC is responsible for reporting all pertinent information relative to the data breach.
Risk
The level of impact on agency operations (including mission, functions, image, or reputation), agency assets, or individuals resulting from the operation of an information system given the potential impact of a threat and the likelihood of that threat occurring.
Risk Assessment
The process of identifying risks to agency operations (including mission, functions, image, or reputation), agency assets, or individuals by determining the probability of occurrence, the resulting impact, and additional security and privacy controls that would mitigate this impact.
Risk Assessment Code Red
Risk of identity theft or other harm is likely.
Risk Assessment Code Green
Risk of identity theft or other harm is unlikely.
Risk Assessment Code Blue
Same as Code Red but notification could compromise national security, a grand jury investigation, or a criminal investigation.
Risk Assessment Code Orange
Asset doesn’t contain PII and there is no risk of identity theft or other harm.
"Routine" Data Breach
A data breach that is not considered exceptional in any way, especially in the size or degree of the data breach, or the facts and circumstances of the data breach.
Safeguard
Any action, device, procedure, technique, or other measure that reduces a system’s vulnerability to a threat.
Safeguarding Personally Identifiable Information Data Extracts (SPIIDE). Renamed Cybersecurity Information Protection Enhancement Controls (CIPEC) in 2024.
A Data Loss Prevention (DLP) tool within the IRS Cybersecurity toolkit. DLP is technology that scans unencrypted, outbound transmissions to advance data protection and reduce inadvertent disclosures.
Sensitive Information
SBU data (including PII and tax information); generic Plain Language term for readability.
Sensitive But Unclassified (SBU) Data
Any information which if lost, stolen, misused, or accessed or altered without proper authorization, may adversely affect the national interest or the conduct of federal programs (including IRS operations), or the privacy to which individuals are entitled under the Privacy Act (5 USC 552).
Sensitive But Unclassified (SBU). See TD P 15-71, Treasury Security Manual, Chapter III Section 24, Sensitive But Unclassified Information
The term “sensitive but unclassified” originated with the Computer Security Act of 1987. It defined SBU as "any information the loss, misuse, or unauthorized access to, or modification of, could adversely affect the national interest or the conduct of Federal programs, or the privacy to which individuals are entitled under 5 USC 552a (the Privacy Act), but has not been specifically authorized under criteria established by an Executive Order or an act of Congress to be kept classified in the interest of national defense or foreign policy." Examples of such sensitive information include personal financial information and information that discloses law enforcement investigative methods. Other particular classes of information may have additional statutory limits on disclosure that require that information to also be treated as sensitive. Examples include tax information, which is protected by IRC 6103 (26 USC 6103) and advanced procurement information, protected by the Procurement Integrity Act (41 USC 423).
Situational Awareness Management Center (SAMC)
SAMC is tasked with promptly reporting all physical security incidents and/or threats.
Tax Information
The term "tax information" refers to a taxpayer’s return and return information protected from unauthorized disclosure under IRC 6103. The law defines return information as any information the IRS has about a tax return or liability determination. Tax information in IRS business processes comes under many names, such as federal tax information (FTI), IRC 6103 protected information, taxpayer data, taxpayer information, tax return information, return information, case information, SBU data, and PII. See IRM 10.5.1, Privacy and Information Protection, Privacy Policy, for additional information.
TCSIRC
Treasury Computer Security Incident Response Center
TSOC (formerly GSOC)
Treasury Shared Services Security Operations Center (formerly Treasury Government Security Operations Center)
Get a plain-English answer with a citation back to this text.
Ask AI about this code