← Back to Library
IRS 1075

IRS Publication 1075 (v1.0)

Full Name:
Internal Revenue Service (IRS) Publication 1075
Acronym:
IRS Pub 1075
Type:
US Federal Standard
Organization:
Internal Revenue Service
Version:
1
Year Published:
2021
Popularity:
Low

Overview of IRS Publication 1075

IRS Publication 1075, published by the Internal Revenue Service in 2021, establishes comprehensive security requirements specifically designed to protect Federal Tax Information (FTI) handled by federal, state, and local government agencies, as well as contractors and other authorized recipients. This publication implements the requirements of Internal Revenue Code (IRC) Section 6103(p)(4), which mandates that agencies receiving FTI establish safeguards to protect the confidentiality of tax information. Unlike general information security frameworks, IRS Publication 1075 addresses the unique legal and regulatory requirements associated with handling highly sensitive tax data, recognizing that unauthorized disclosure of FTI can result in severe legal consequences, identity theft, and violations of taxpayer privacy rights.

The publication emerged from the IRS's responsibility to ensure that agencies receiving FTI maintain appropriate security controls, recognizing that tax information represents some of the most sensitive personal and financial data collected by the federal government. IRS Publication 1075 provides detailed requirements covering physical security, information systems security, personnel security, incident response, and ongoing monitoring, ensuring that FTI is protected throughout its lifecycle from receipt through disposal. The framework recognizes that agencies handling FTI must balance security requirements with operational needs, providing flexibility while maintaining strict security standards.

IRS Publication 1075 applies to any federal, state, or local agency that receives, processes, stores, or transmits FTI, as well as contractors and other entities authorized to handle tax information. The publication establishes mandatory security requirements that agencies must implement to maintain authorization to receive FTI, with non-compliance potentially resulting in suspension or termination of FTI access. The framework provides comprehensive guidance that enables agencies to establish security programs appropriate for their specific environments while meeting federal requirements for FTI protection.

Regulatory Requirements and Applicability

IRS Publication 1075 carries mandatory compliance requirements under IRC Section 6103(p)(4), which requires agencies receiving FTI to establish safeguards protecting the confidentiality of tax information. Federal agencies, state agencies, local agencies, and contractors receiving FTI must implement the security requirements specified in IRS Publication 1075 as a condition of receiving and maintaining authorization to access tax information. Non-compliance can result in immediate suspension of FTI access, contract termination, financial penalties, and potential legal action under federal law.

The publication applies to agencies at all levels of government that receive FTI for various purposes including income verification for benefit programs, tax administration, law enforcement, and other authorized uses. Agencies must undergo security reviews and obtain authorization from the IRS before receiving FTI, and must maintain compliance with IRS Publication 1075 requirements throughout their authorization period. The IRS conducts periodic security reviews and audits to verify compliance, and agencies must demonstrate that security controls are implemented effectively and maintained continuously.

Covered organizations must implement comprehensive security controls, maintain detailed documentation of security practices, conduct regular security assessments, and report security incidents promptly to the IRS. Agencies must designate security officers responsible for FTI security, establish security policies and procedures, provide security training to personnel, and implement technical and physical security controls appropriate for their environments. Compliance is not optional—agencies that fail to meet IRS Publication 1075 requirements risk losing authorization to receive FTI, which can severely impact their ability to perform authorized functions.

Key Framework Components and Control Domains

IRS Publication 1075 organizes security requirements into several key domains that address the full spectrum of FTI protection needs. These domains recognize that effective FTI security requires comprehensive controls covering physical security, information systems security, personnel security, and operational security.

Physical Security Requirements

IRS Publication 1075 requires agencies to implement comprehensive physical security controls that protect FTI from unauthorized access, theft, and environmental hazards. Physical security requirements address facility access controls, secure storage areas, visitor management, and environmental protections. Agencies must establish secure areas where FTI is processed and stored, implement access controls that restrict entry to authorized personnel only, and maintain visitor logs and escort procedures for non-authorized individuals.

The publication requires agencies to implement physical security controls appropriate for their environments, recognizing that different agencies may have different facility types and security needs. Secure storage areas must be protected by locks, access control systems, or other physical barriers that prevent unauthorized access. Agencies must ensure that FTI is not left unattended in unsecured areas, that workstations displaying FTI are protected from unauthorized viewing, and that FTI in physical form is stored securely when not in use. Physical security controls must be documented, tested regularly, and maintained effectively throughout the authorization period.

Information Systems Security

IRS Publication 1075 mandates comprehensive information systems security controls that protect FTI stored, processed, or transmitted through information systems. Information systems security requirements address access controls, authentication mechanisms, encryption, network security, system hardening, and security monitoring. Agencies must implement strong authentication mechanisms including multi-factor authentication for access to systems containing FTI, establish access controls that enforce least privilege principles, and implement encryption for FTI both at rest and in transit.

The publication requires agencies to implement network security controls that protect FTI from unauthorized access, including firewalls, network segmentation, and intrusion detection systems. System hardening requirements mandate that systems processing FTI are configured securely, patched regularly, and protected from known vulnerabilities. Agencies must implement security monitoring capabilities that detect unauthorized access attempts, security incidents, and policy violations, and must maintain audit logs of all access to FTI. Information systems security controls must be tested regularly, updated as threats evolve, and documented comprehensively.

Personnel Security and Training

IRS Publication 1075 requires agencies to implement personnel security controls that ensure only authorized, trustworthy individuals access FTI. Personnel security requirements address background investigations, security clearances, security training, and ongoing personnel management. Agencies must conduct background investigations for personnel who will access FTI, ensuring that individuals have appropriate clearances and do not pose security risks. Personnel must receive security training before accessing FTI and must complete ongoing security awareness training regularly.

The publication requires agencies to establish clear security responsibilities for personnel, ensure that personnel understand their obligations to protect FTI, and implement procedures for reporting security incidents and policy violations. Agencies must maintain records of personnel security clearances, training completion, and access authorizations, and must revoke access promptly when personnel no longer require access or when security concerns arise. Personnel security controls must be integrated into standard human resources processes, ensuring that security considerations are addressed throughout the employment lifecycle.

Access Control and Identity Management

IRS Publication 1075 mandates comprehensive access control requirements that ensure FTI is accessible only to authorized personnel for authorized purposes. Access control requirements address user identification, authentication, authorization, and access management. Agencies must implement strong authentication mechanisms including multi-factor authentication for access to FTI, establish access controls that enforce least privilege principles, and conduct regular access reviews to ensure that access authorizations remain appropriate.

The publication requires agencies to implement access controls that restrict access based on job functions, ensure that users can only access FTI necessary for their duties, and prevent unauthorized access through technical and procedural controls. Access management processes must include procedures for granting access, modifying access, and revoking access when no longer needed. Agencies must maintain comprehensive access logs that record all access to FTI, enabling audit trails and security monitoring. Access control implementations must be tested regularly, reviewed for effectiveness, and updated as organizational needs change.

Encryption and Data Protection

IRS Publication 1075 requires agencies to implement encryption and data protection controls that protect FTI from unauthorized disclosure. Encryption requirements mandate that FTI is encrypted both at rest and in transit, using encryption mechanisms that meet federal standards. Agencies must implement encryption for FTI stored on devices, servers, and backup media, and must encrypt FTI transmitted across networks including email, file transfers, and remote access connections.

The publication requires agencies to implement data protection controls that prevent unauthorized disclosure, including data loss prevention technologies, secure deletion procedures, and media sanitization processes. Agencies must ensure that FTI is not stored on unencrypted portable devices unless absolutely necessary and properly protected, and must implement secure disposal procedures that ensure FTI cannot be recovered from disposed media. Data protection controls must address the full FTI lifecycle, from receipt through disposal, ensuring that FTI remains protected throughout its existence in agency systems.

Incident Response and Breach Notification

IRS Publication 1075 mandates comprehensive incident response requirements that ensure agencies can detect, respond to, and recover from security incidents affecting FTI. Incident response requirements address incident detection, response procedures, breach notification, and recovery activities. Agencies must establish incident response plans that define procedures for identifying security incidents, containing incidents, eradicating threats, recovering systems, and notifying appropriate parties including the IRS.

The publication requires agencies to report security incidents to the IRS promptly, including unauthorized access, data breaches, and policy violations. Breach notification procedures must ensure that incidents are reported within required timeframes, that incident details are documented comprehensively, and that remediation activities are tracked and verified. Agencies must conduct post-incident reviews to identify lessons learned, update security controls based on incident findings, and improve incident response capabilities. Incident response plans must be tested regularly, updated as threats evolve, and integrated with broader agency security programs.

Security Monitoring and Audit

IRS Publication 1075 requires agencies to implement security monitoring and audit capabilities that detect security events, verify compliance, and support security management. Security monitoring requirements address continuous monitoring, security event detection, audit logging, and security reporting. Agencies must implement monitoring capabilities that detect unauthorized access attempts, security policy violations, and suspicious activities, and must maintain comprehensive audit logs of all access to FTI.

The publication requires agencies to conduct regular security assessments, internal audits, and compliance reviews to verify that security controls are implemented effectively and that requirements are met. Security monitoring must be continuous, automated where possible, and reviewed regularly by security personnel. Audit logs must be protected from tampering, retained for appropriate periods, and reviewed regularly to identify security events. Agencies must report security monitoring results to management and the IRS, and must use monitoring findings to improve security controls and address security weaknesses.

Implementation Strategies and Best Practices

Successfully implementing IRS Publication 1075 requires agencies to establish comprehensive security programs, integrate FTI security into standard operations, and maintain compliance continuously. Agencies should begin by conducting comprehensive gap assessments comparing current security practices against IRS Publication 1075 requirements, identifying security weaknesses, and developing implementation plans that address gaps systematically.

Establish FTI Security Governance: Agencies must establish clear governance structures for FTI security, designating security officers responsible for FTI protection, establishing security policies and procedures, and ensuring that FTI security receives appropriate management attention. Governance structures should include security committees, regular security reporting to management, and clear accountability for security outcomes. Security officers must have appropriate authority, resources, and expertise to manage FTI security effectively.

Conduct Comprehensive Security Assessments: Before receiving FTI authorization, agencies must conduct comprehensive security assessments that evaluate physical security, information systems security, personnel security, and operational security. Security assessments should identify security weaknesses, evaluate risks, and develop remediation plans. Agencies should work with the IRS during the authorization process, addressing security concerns and demonstrating that security requirements can be met effectively.

Implement Physical Security Controls: Agencies must implement physical security controls appropriate for their facilities, including secure storage areas, access controls, visitor management, and environmental protections. Physical security controls should be designed to prevent unauthorized access to FTI, protect FTI from theft or damage, and ensure that FTI is handled securely in physical form. Agencies should document physical security controls, test controls regularly, and update controls as facility needs change.

Establish Information Systems Security: Agencies must implement comprehensive information systems security controls including access controls, authentication mechanisms, encryption, network security, and security monitoring. Information systems security should be integrated into standard IT operations, ensuring that FTI security requirements are addressed throughout system lifecycles. Agencies should implement security controls that meet federal standards, test security controls regularly, and update controls as threats evolve.

Implement Personnel Security Programs: Agencies must establish personnel security programs that ensure only authorized, trustworthy individuals access FTI. Personnel security programs should include background investigations, security training, ongoing security awareness, and access management. Agencies should integrate personnel security into standard human resources processes, ensuring that security considerations are addressed throughout employment lifecycles.

Establish Incident Response Capabilities: Agencies must develop incident response capabilities that enable prompt detection, response, and recovery from security incidents. Incident response plans should define procedures for identifying incidents, containing threats, notifying appropriate parties, and recovering systems. Agencies should test incident response plans regularly, update plans based on lessons learned, and ensure that incident response personnel are trained and prepared.

Implement Continuous Monitoring: Agencies must implement continuous security monitoring that detects security events, verifies compliance, and supports security management. Security monitoring should include automated monitoring tools, regular log reviews, security assessments, and compliance audits. Agencies should use monitoring findings to improve security controls, address security weaknesses, and demonstrate compliance to the IRS.

Relationship to Other Frameworks and Standards

IRS Publication 1075 exists within a broader ecosystem of federal security frameworks and standards, with important relationships to other federal requirements that help agencies manage multiple compliance obligations efficiently.

IRS Publication 1075 aligns closely with NIST Cybersecurity Framework (CSF), with many security requirements mapping to NIST CSF functions and categories. Agencies implementing NIST CSF can extend their cybersecurity programs to include IRS Publication 1075 requirements, creating integrated security programs that address both general cybersecurity and FTI-specific security needs. The frameworks share common themes including risk-based approaches, continuous monitoring, and comprehensive security management, making them complementary rather than competing requirements.

The publication relates to NIST SP 800-53, which provides security controls for federal information systems. Agencies subject to NIST SP 800-53 can map IRS Publication 1075 requirements to NIST controls, implementing security controls that satisfy both requirements. Many IRS Publication 1075 requirements align with NIST SP 800-53 controls, enabling agencies to implement security controls once while meeting multiple requirements.

IRS Publication 1075 aligns with ISO/IEC 27001 and ISO/IEC 27002, sharing common information security management principles while addressing FTI-specific requirements. Agencies implementing ISO 27001 can extend their information security management systems to include IRS Publication 1075 requirements, creating integrated security programs that address both general information security and FTI protection. The standards share common elements including risk assessment methodologies, security control implementation, and continuous improvement processes.

For agencies operating in cloud environments, IRS Publication 1075 relates to FedRAMP requirements, recognizing that cloud service providers must meet security requirements appropriate for FTI. Agencies using cloud services for FTI must ensure that cloud providers meet IRS Publication 1075 requirements or equivalent security standards, and must implement additional controls to protect FTI in cloud environments.

Common Challenges and Solutions

Agencies implementing IRS Publication 1075 frequently encounter similar challenges related to the comprehensive nature of requirements, resource constraints, and the need to balance security with operational needs. Understanding these common challenges helps agencies plan proactively and implement security requirements effectively.

Implementing Comprehensive Security Controls: IRS Publication 1075 includes extensive security requirements covering physical security, information systems security, personnel security, and operational security, which can be overwhelming for agencies to implement comprehensively. Agencies may struggle to understand requirements, prioritize implementation activities, and ensure comprehensive coverage. Solutions include conducting comprehensive gap assessments, developing phased implementation plans, prioritizing high-risk areas, and leveraging external expertise. Agencies should approach implementation systematically, addressing requirements progressively and building toward comprehensive coverage over time.

Balancing Security Requirements with Operational Needs: FTI security requirements can impact agency operations, creating tension between security controls and operational efficiency. Security controls that restrict access, require additional authentication, or limit functionality can create operational challenges. Solutions include designing security controls that work within operational constraints, involving operational personnel in security design decisions, and implementing security controls that enable operations while providing effective protection. Agencies should balance security with operational needs, ensuring that security controls support agency missions while protecting FTI effectively.

Maintaining Compliance Continuously: IRS Publication 1075 requires continuous compliance, with agencies maintaining security controls throughout their authorization periods. Maintaining compliance can be challenging, requiring agencies to keep security controls current, conduct regular assessments, and address security weaknesses promptly. Solutions include establishing continuous monitoring processes, integrating compliance activities into standard operations, and maintaining comprehensive documentation. Agencies should approach compliance as an ongoing activity rather than a one-time achievement, ensuring that security controls remain effective and requirements are met continuously.

Managing Third-Party Security: Agencies often rely on contractors and service providers for FTI processing, creating challenges for ensuring that third parties meet security requirements. Third-party security management can be complex, requiring agencies to assess vendor security, establish contractual requirements, and monitor vendor compliance. Solutions include conducting comprehensive vendor security assessments, establishing clear contractual security requirements, implementing vendor monitoring processes, and ensuring that vendors understand their security obligations. Agencies should ensure that third-party security is managed effectively, protecting FTI throughout vendor relationships.

Responding to Security Incidents Effectively: Agencies must be prepared to respond to security incidents affecting FTI, but incident response can be challenging, particularly for agencies with limited security resources. Incident response requires capabilities for detecting incidents, containing threats, notifying appropriate parties, and recovering systems. Solutions include developing comprehensive incident response plans, training incident response personnel, testing incident response procedures regularly, and establishing relationships with external security experts. Agencies should ensure that incident response capabilities are maintained effectively, enabling prompt and effective response to security incidents.

Demonstrating Compliance to the IRS: Agencies must demonstrate compliance with IRS Publication 1075 requirements through security reviews, audits, and ongoing reporting. Demonstrating compliance can be challenging, requiring agencies to maintain comprehensive documentation, conduct regular assessments, and report security status accurately. Solutions include maintaining detailed security documentation, conducting regular internal assessments, preparing for IRS reviews proactively, and addressing security weaknesses promptly. Agencies should ensure that compliance evidence is maintained comprehensively, enabling effective demonstration of compliance to the IRS.

Audit and Compliance Validation

IRS Publication 1075 requires agencies to demonstrate compliance through comprehensive security reviews, audits, and ongoing monitoring. The IRS conducts initial security reviews before authorizing agencies to receive FTI, periodic security reviews during authorization periods, and audits to verify compliance. Agencies must maintain comprehensive documentation of security controls, conduct regular internal assessments, and report security status to the IRS.

Initial security reviews evaluate agency security programs, identifying security strengths and weaknesses, and determining whether agencies meet requirements for FTI authorization. Agencies must address security weaknesses identified during initial reviews, demonstrate that security requirements can be met, and obtain IRS authorization before receiving FTI. Initial reviews are comprehensive, evaluating all aspects of agency security programs including physical security, information systems security, personnel security, and operational security.

Periodic security reviews evaluate ongoing compliance, verifying that security controls remain effective and that requirements continue to be met. Agencies must participate in periodic reviews, provide requested documentation, and address security concerns identified during reviews. Periodic reviews may be scheduled or unscheduled, and agencies must be prepared to demonstrate compliance at any time. Agencies should conduct regular internal assessments to identify security weaknesses before IRS reviews, enabling proactive remediation and demonstrating commitment to compliance.

Security audits provide detailed evaluation of agency security programs, testing security controls, reviewing documentation, and verifying compliance. Audits may be conducted by the IRS or authorized third parties, and agencies must cooperate fully with audit activities. Audit findings may identify security weaknesses requiring remediation, and agencies must address audit findings promptly to maintain FTI authorization. Agencies should prepare for audits proactively, maintaining comprehensive documentation and ensuring that security controls are implemented effectively.

Frequently Asked Questions

Who must comply with IRS Publication 1075?

IRS Publication 1075 applies to any federal, state, or local agency that receives, processes, stores, or transmits Federal Tax Information (FTI), as well as contractors and other entities authorized to handle tax information. Compliance is mandatory under Internal Revenue Code Section 6103(p)(4), and agencies must implement security requirements as a condition of receiving and maintaining authorization to access FTI. Non-compliance can result in suspension of FTI access, contract termination, and potential legal action.

What are the key security requirements in IRS Publication 1075?

IRS Publication 1075 establishes comprehensive security requirements covering physical security, information systems security, personnel security, access controls, encryption, incident response, and security monitoring. Key requirements include implementing secure storage areas, strong authentication mechanisms, encryption for FTI at rest and in transit, comprehensive access controls, incident response plans, and continuous security monitoring. Agencies must implement security controls appropriate for their environments while meeting federal requirements for FTI protection.

How does IRS Publication 1075 relate to other federal security frameworks?

IRS Publication 1075 aligns with NIST Cybersecurity Framework, NIST SP 800-53, and ISO 27001, sharing common security principles while addressing FTI-specific requirements. Agencies implementing other federal security frameworks can extend their security programs to include IRS Publication 1075 requirements, creating integrated security programs that address both general cybersecurity and FTI protection. Many requirements map across frameworks, enabling agencies to implement security controls once while meeting multiple requirements.

What happens if an agency fails to comply with IRS Publication 1075?

Non-compliance with IRS Publication 1075 can result in immediate suspension of FTI access, contract termination, financial penalties, and potential legal action under federal law. The IRS may conduct security reviews and audits to verify compliance, and agencies that fail to meet requirements risk losing authorization to receive FTI. Agencies must maintain compliance continuously throughout their authorization periods, addressing security weaknesses promptly and demonstrating that security requirements are met effectively.

How do agencies obtain authorization to receive FTI?

Agencies must undergo comprehensive security reviews and obtain authorization from the IRS before receiving FTI. The authorization process includes security assessments, evaluation of security programs, and demonstration that security requirements can be met. Agencies must address security weaknesses identified during reviews, implement required security controls, and obtain IRS authorization before receiving FTI. Authorization must be maintained through ongoing compliance, periodic security reviews, and prompt remediation of security weaknesses.

Conclusion

IRS Publication 1075 provides essential security requirements for federal, state, and local agencies handling Federal Tax Information, ensuring that highly sensitive tax data is protected throughout its lifecycle. As a mandatory federal requirement, IRS Publication 1075 establishes comprehensive security standards that agencies must implement to receive and maintain authorization to access FTI.

Successful IRS Publication 1075 implementation requires agencies to establish comprehensive security programs, integrate FTI security into standard operations, and maintain compliance continuously. Agencies should approach FTI security as an integral part of their security programs rather than separate activities, ensuring that security requirements are met effectively while supporting agency missions.

By following IRS Publication 1075 requirements, maintaining comprehensive documentation, conducting regular security assessments, and addressing security weaknesses promptly, agencies can protect FTI effectively, maintain authorization to receive tax information, and demonstrate commitment to protecting taxpayer privacy. The investment in FTI security pays dividends through reduced security incidents, maintained authorization, enhanced trust, and strengthened ability to perform authorized functions while protecting sensitive tax information.