Error status
TIGTA's previous website is temporarily unavailable. We are providing this interim website to keep you informed about our latest reports and how you can submit a complaint or report fraud, waste, and abuse within IRS programs or by IRS employees.
Breadcrumb
TIGTA: IRS2GO Smartphone Application Is Secure
September 20, 2011
TIGTA - 2011-57 Karen Kraushaar karen.kraushaar@tigta.treas.gov TIGTACommunications@tigta.treas.gov (202) 622-6500
TIGTA: IRS2GO Smartphone Application Is Secure
Washington - The Internal Revenue Service’s (IRS) IRS2GO mobile application for the AppleiPhone® and the Google Android® smartphones is secure, according to a new report from theTreasury Inspector General for Tax Administration (TIGTA).
The IRS2GO application is the first mobile application developed by the IRS. It allows users tocheck the status of their tax refunds and receive tax tips. Since its release on January 20, 2011,147,205 iPhone users and 178,773 Android users have downloaded the mobile application.
TIGTA reviewed whether the IRS adequately tested and secured the IRS2GO smartphoneapplication.
TIGTA found that the IRS2GO application adequately secures data communications and doesnot store sensitive or Personally Identifiable Information (PII) such as Social Security Numberson smartphones. However, the IRS did not follow appropriate processes for using aprogramming language that had not been approved by IRS information technology managementand open-source software during the software development. The IRS said it made a risk-baseddecision not to pursue waivers in consideration of time constraints for the project.
TIGTA also found that the IRS did not comply with Office of Management and Budget CircularA-130, which requires senior officials to approve the application before its public release.
“The IRS is to be commended for using technology to make tax information more accessible totaxpayers,” said J. Russell George, the Treasury Inspector General for Tax Administration.However, I am troubled that the IRS took some shortcuts in developing the application. Whileno significant security problems were identified, development of future smartphone applicationsshould follow approved processes to avoid introducing unnecessary risk into the developmentprocess."
TIGTA recommended that the IRS follow software development processes and comply withpolicies when developing new smartphone applications. IRS officials agreed with therecommendations.

