The IRS has issued new security guidelines, specifically mandating the implementation of multi-factor authentication (MFA) for all tax professionals. This crucial update, stemming from the Federal Trade Commission’s safeguards rule effective June 2023, is intended to improve the protection of sensitive client information. MFA requires tax professionals to use at least two distinct forms of verification—such as a password combined with a text message code or biometric identification like a fingerprint scan—to access systems, applications, or devices. These measures are designed to significantly enhance security and reduce the risk of unauthorized access to confidential data.
To safeguard federal tax information (FTI), agencies must follow strict security guidelines. One key requirement is that all access to FTI must be through secure, agency-owned equipment. Additionally, any remote access needs to have multi-factor authentication (MFA) in place. Remote access means connecting to an agency's system through any external network.
What is Multi-Factor Authentication?
Multi-factor authentication is a security process that requires users to provide two or more verification factors to access a system. It is sometimes referred to as two-factor authentication (2FA). This greatly reduces the risk of unauthorized access and identity theft. Here's a breakdown of the main categories of authentication factors:
- Something You Know: This includes passwords, PINs, challenge questions (like your mother’s maiden name or your high school mascot), or identifying patterns. For strong security, passwords should be at least fourteen characters long and include a mix of letters, numbers, and special characters.
- Something You Have: This refers to physical items like hardware tokens (e.g., RSA SecurID fob) or software tokens. Tokens generate unique codes that users must enter to verify their identity. There are two types:
- Hardware Tokens: Physical devices that generate codes or require a PIN.
- Software Tokens: Authenticator applications on devices like computers or smartphones that produce codes. These need to be protected against viruses and other software threats.
- Something You Are: This involves biometric data such as fingerprints, voiceprints, or iris scans. Biometrics are often used along with passwords for added security, like in the case of unlocking an iPhone or Android smartphone.
Implementing MFA
When implementing MFA, tax professionals should ensure:
- Two-Factor Minimum: MFA must involve at least two different types of authentication, hence the term “2FA”.
- Secure Tokens: Tokens should be encrypted, with non-exportable private keys, and should not be stored in plain text.
- Confidential Channels: Information like seed records and initial passphrases must be shared confidentially.
- Regular Activation: Each authentication attempt should require manual entry of a PIN or password.
- Audit and Update: Regularly audit access logs and update malware prevention software.
Best Practices for Tax Professionals
To recap, there are several things American tax professionals should do to comply with the IRS's updated security requirements and effectively implement multi-factor authentication (MFA). First, ensure that all systems and software used for managing client information are configured to support MFA. Regularly update passwords and employ complex, unique combinations to further protect access points. Additionally, educate staff and clients about the importance of MFA and how to use it properly. Conduct routine security audits to identify and address any vulnerabilities. All of these pointers will help you avoid potential security breaches and maintain the trust of your clients.
Mandatory Written Information Security Programs (WISPs)
In addition to the IRS’s multi-factor authentication requirements, tax professionals are also mandated to develop and implement a Written Information Security Program (WISP). A WISP is a comprehensive plan that outlines the procedures and protocols for protecting client data from unauthorized access, breaches, and other security threats. This program should include detailed policies on data handling, employee training, incident response, and regular security assessments.
Creating a well-thought-out WISP can be a complex and time-consuming task, but it is important for ensuring compliance and maintaining a secure environment. CountingWorks AI offers immense value in this area – the system has the ability to create effective WISPs tailored to their specific needs.
The IRS’s new mandate for multi-factor authentication represents a critical step towards fortifying the security of sensitive financial data. By implementing these best practices, tax and accounting professionals can provide their clients with peace of mind against emerging threats, like the recent Social Security number breach that made international headlines. Adhering to enhanced security measures will ultimately contribute to a stronger defense against data leaks and maintain client confidence.