Data Protection & Privacy
DETAIL

U.S. IRS Publication 1075 — Tax Information Security Guidelines for Federal, State, and Local Agencies

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

IRS Publication1075 is a federal information security guideline that helpsgovernment agencies and their partners protect Federal TaxInformation (FTI) through robust cybersecurity controls andcompliance practices. The publication sets forth requirements toensure the confidentiality, integrity, and availability of tax datahandled by federal, state, local, and tribal agencies, as well astheir contractors.

Issued by theU.S. Internal Revenue Service (IRS), Publication 1075 applies to anyorganization that receives, processes, stores, or transmits FTI. Itoutlines comprehensive requirements covering areas such as accesscontrol, incident response, risk assessment, physical security, andaudit logging to safeguard sensitive tax information and maintainregulatory compliance.

Agencies andcontractors implement IRS Publication 1075 by embedding itsrequirements into their security programs, conducting regular riskassessments, maintaining detailed documentation, and supporting auditreadiness. The framework commonly aligns with broader securitystandards like NIST SP 800-53, helping organizations strengthencybersecurity posture while fulfilling IRS compliance obligations.

Why it Matters

IRS Publication1075 helps agencies and contractors safeguard Federal Tax Informationthrough comprehensive controls, supporting data confidentiality,regulatory compliance, and audit preparedness.

Key benefitsinclude:

•  Strengthen data protection practices

Ensure theconfidentiality and integrity of tax information with strict accesscontrols and monitoring requirements across IT environments.

•  Enhance regulatory alignment

Align securitymeasures with federal guidelines and standards to support statutoryobligations and facilitate consistent compliance reporting.

•  Increase audit readiness

Maintaindetailed documentation, policies, and procedures to demonstratecompliance and facilitate efficient responses during audits orreviews.

•  Improve incident detection and response

Implement robustincident management protocols, helping organizations quicklyidentify, report, and mitigate security breaches involving tax data.

•  Promote operational resilience

Reduce risks ofservice disruption and data loss by requiring ongoing riskassessments and effective physical and logical safeguards.

How it Works

U.S. IRSPublication 1075 establishes a comprehensive set of regulatoryrequirements and security safeguards aimed at protecting Federal TaxInformation (FTI) handled by federal, state, and local agencies. Theframework structures its guidelines into key domains including accesscontrol, physical security, incident response, media protection, andrisk management, drawing from established best practices andintegrating specific obligations for safeguarding FTI. Theserequirements are mapped to detailed security controls and auditprocedures that facilitate ongoing compliance monitoring.

In practice,agencies implement IRS Publication 1075 by adopting mandated securitycontrols, conducting regular risk assessments, and mapping thesecontrols to their internal governance programs. Organizationsundertake ongoing compliance reviews, monitor their security posture,and maintain procedures for reporting and responding to potentialincidents. This operational approach supports secure handling,sharing, and storage of FTI, and ensures continuous alignment withevolving IRS regulatory expectations.

With SmartSuite,organizations operationalize IRS Publication 1075 by leveragingcontrol libraries tailored to FTI security practices, maintainingrisk registers, and managing policy governance. The platform enablesevidence collection, compliance tracking, and supports remediationworkflows to address audit findings. Dashboards and reportingfeatures facilitate audit readiness by providing visibility intocompliance activities and ongoing monitoring efforts.

Key Elements

•  Access Control Requirements

Specifiesprocedures and mechanisms for managing user identities andrestricting access to Federal Tax Information systems.

•  Audit and Accountability Measures

Describesrequirements for system logging, monitoring, and maintaining recordsto support transparency and compliance.

•  Physical and Environmental Security

Outlinessafeguards to protect physical locations housing FTI, includingfacility access and environmental controls.

•  Risk Assessment Processes

Establishespractices for regularly evaluating threats, vulnerabilities, and theeffectiveness of implemented security controls.

•  Incident Response Protocols

Definesstructured procedures for detecting, reporting, and addressingsecurity incidents involving FTI.

•  Data Protection and Encryption

Organizesrequirements for securing data in transit and at rest to preventunauthorized disclosure.

•  Training and Security Awareness

Details ongoingeducation programs to ensure personnel understand privacy obligationsand secure handling practices for FTI.

Framework Scope

IRS Publication1075 is implemented by federal, state, local, and tribal agencies, aswell as contractors, that access or handle Federal Tax Information(FTI). The framework governs the security of information systems andphysical environments processing tax data and is commonly applied tosupport regulatory compliance and data protection efforts for auditand assurance programs.

Framework Objectives

IRS Publication1075 outlines essential security controls and risk managementpractices for safeguarding federal tax information (FTI).

•  Protect the confidentiality and integrity of tax data throughcomprehensive data protection measures

•  Strengthen cybersecurity governance and oversight fororganizations handling federal tax information

•  Enhance compliance with federal data protection, privacy, andregulatory requirements

•  Establish effective risk management strategies to reduce thelikelihood of data breaches

•  Support consistent audit readiness with documented securitycontrols and compliance processes

•  Promote operational resilience by maintaining robust incidentresponse and recovery procedures IRS Publication 1075 aligns closelywith NIST SP 800-53 and FISMA, focusing on the protection of federaltax information (FTI). Government agencies and contractors implementit to meet federal and state regulatory obligations, oftenintegrating it with frameworks like ISO 27001 or PCI DSS forcomprehensive data security and compliance assurance.

Common Framework Mappings

IRS Publication1075 is often mapped to other widely adopted security and privacyframeworks to streamline compliance, enable shared controls, andreduce audit complexity for organizations handling sensitive taxinformation.

Mappedframeworks include:

CIS Controls

COBIT

FedRAMP

FISMA

HIPAA

ISO/IEC 27001

NISTCybersecurity Framework

NIST SP 800-53

PCI DSS

SOC 2

At a Glance
IRS Publication 1075
  • checklist
    Classicifation
    Category
    info
    Data Protection & Privacy
    Domain
    info
    Privacy
    Framework Family
    info
    NIST Special Publications
  • info
    Regulatory Context
    Type
    info
    Guidance
    Legal Instrument
    info
    Guideline
    Sector
    info
    Government Sector
    Industry
    info
    Government & Public Sector
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    North America
    Region Detail
    info
    United States
    Publisher
    info
    United States. Internal Revenue Service. Office of Safeguards
  • published_with_changes
    Versioning
    Version
    info
    2021
    Effective Date
    info
    June 10, 2022
    Issue Date
    info
    September 2016
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

IRS Publication 1075 is publicly available for free on the IRS website. License included with platform

Official Resources
IRS Publication 1075
Provides guidelines for safeguarding federal tax information by state and local agencies.
chevron_forward
SMARTSUITE

How SmartSuite Supports IRS Pub 1075

Manage federal tax information security requirements by organizing IRS Publication 1075 safeguards, tracking implementation tasks, and maintaining evidence protecting Federal Tax Information (FTI) across systems and partners.

FTI Safeguard Control Library

Structure IRS Pub 1075 safeguards for access control, encryption, monitoring, and system protection.

FTI Asset and Data Handling Governance

Track systems, applications, and processes that store, transmit, or process Federal Tax Information.

FTI Risk Assessment and Safeguard Tracking

Manage risk assessments, safeguard implementation tasks, and remediation plans tied to FTI systems.

Access Management and Workforce Compliance

Manage user access approvals, background checks, and role-based permissions for personnel handling FTI.

FTI Security Incident Tracking and Reporting

Track security incidents affecting FTI and maintain required reporting and response workflows.

IRS Safeguard Review Readiness Reporting

Provide dashboards tracking safeguard implementation status and readiness for IRS safeguard reviews.

Related frameworks

CJIS Security Policy

The CJIS Security Policy requires security and privacy controls to protect the confidentiality, integrity, and availability of Criminal Justice Information.

Learn More
arrow_forward
FedRAMP Rev. 5

FedRAMP standardizes security requirements to assess, authorize, and continuously monitor cloud services that handle U.S. federal data.

Learn More
arrow_forward
FISMA

FISMA is a U.S. law requiring federal agencies and contractors to secure government information systems and manage cybersecurity risks.

Learn More
arrow_forward
GLBA Safeguards Rule (16 CFR Part 314)

The GLBA Safeguards Rule requires financial institutions to implement security programs to protect consumer financial information.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
NIST 800-171 Rev.2

NIST SP 800-171 defines security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.

Learn More
arrow_forward
SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For IRS Publication 1075 (Tax Information Security Guidelines)

What is IRS Publication 1075 used for?

IRS Publication 1075 establishes the security requirements that federal, state, and local agencies must follow to protect federal tax information (FTI). The framework sets out controls and safeguards to maintain the confidentiality of FTI throughout its lifecycle, including storage, transmission, processing, and disposal.

Is compliance with IRS Publication 1075 mandatory?

Yes, compliance with IRS Publication 1075 is mandatory for any agency or entity that receives or processes FTI from the IRS. It is a condition for receiving FTI and non-compliance can result in loss of access to this information and potential legal penalties.

Who does IRS Publication 1075 apply to?

IRS Publication 1075 applies to all federal, state, and local agencies, contractors, and other entities that receive, handle, or store FTI. The framework’s applicability is determined by whether an organization has access to FTI as part of its operations or contractual functions.

What security controls are required by IRS Publication 1075?

IRS Publication 1075 requires implementation of a range of safeguards, including physical security, logical access controls, encryption, incident response plans, and employee background checks. Agencies must also develop written policies and procedures addressing the handling and safeguarding of FTI.

How do agencies implement IRS Publication 1075 requirements?

Agencies implement IRS Publication 1075 by conducting risk assessments, documenting security controls, training staff, and conducting regular internal inspections. Ongoing monitoring and remediation of deficiencies identified during audits or inspections are essential components of effective implementation.

How does IRS Publication 1075 relate to other security frameworks?

IRS Publication 1075 aligns closely with federal standards such as NIST SP 800-53, but it includes IRS-specific requirements and emphasis on FTI protection. Agencies often map IRS Publication 1075 controls against NIST frameworks to streamline compliance efforts when subject to multiple regulatory requirements.

What are the ongoing compliance and audit requirements for IRS Publication 1075?

To maintain compliance, agencies must perform annual safeguard reviews, conduct periodic risk assessments, and report incidents involving FTI to the IRS Office of Safeguards. Regular audits and inspections are required to verify that controls remain effective and that any deficiencies are promptly addressed.

How would SmartSuite support IRS Publication 1075?

SmartSuite can help organizations manage IRS Publication 1075 compliance by providing tools for risk tracking, control management, and evidence collection. The platform supports audit readiness through automated workflows, centralized documentation, and real-time reporting, ensuring continuous compliance and streamlined communication with auditors and oversight authorities.

NEXT STEP

Put CRI Profile into action with SmartSuite

Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

Explore in SmartSuite
chevron_forward
View all Frameworks
chevron_forward