Note:
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
The acronym was previously "TSSSOC" . It was updated to "TSOC" per Treasury’s Departmental Incident Response Plan (IRP) dated October 2024.
Theft
An asset, electronic or hardcopy, thought or known to have been taken without permission from the individual who is responsible for the asset.
Third-Party Data Owner
Data owner external to the IRS.
Third-Party Data Breach
An event that results from the unauthorized use or loss of SBU data (including PII and tax information) that does not involve IRS systems, applications, or online services. Third-party data breaches can be reported to the IRS by external sources, such as practitioners, software developers, state and local agencies, or others.
Treasury Inspector General for Tax Administration (TIGTA)
Provides oversight of the Department of the Treasury matters involving IRS activities, the IRS Oversight Board and the IRS Office of Chief Counsel.
Unauthorized Access (UNAX)
The willful unauthorized access and/or inspection of tax returns and return information.
Unauthorized Disclosure (UNAD)
An unauthorized and unlawful release of information to an individual who is not authorized to receive the information.
Unreasonable Delay
A delay in notification following the discovery of a data breach beyond that which is necessary to determine the scope of the data breach while considering the needs of law enforcement and national security, and, if applicable, to restore the reasonable integrity of the computerized data system compromised. This means if a data breach is discovered and all the information necessary to determine the scope of the data breach is gathered within 30 days, it is unreasonable to wait until the 45th day to notify the individuals whose information was breached.
Get a plain-English answer with a citation back to this text.
Ask AI about this code