Two audits of the U.S. Internal Revenue Service, issued a day apart by the same watchdog agency, reached different conclusions about how effectively the tax agency manages information risk. One audit found deficiencies with the IRS’s risk-based decisions process that were not in alignment with policy. The other audit found the IRS collects and tracks minimal information about decisions and doesn’t require supporting documents about why decisions were made. The failure to adequately document risk-by decisions means those responsible for making IT security decisions could lack the right information to make sound choices.”]
Source: https://www.cuinfosecurity.com/irs-2-audits-2-conclusions-on-risk-management-a-7564

