Internal Controls


Despite making progress in safeguarding sensitive or confidential information, the SEC still lacks consistency in implementing key data controls, the GAO said in its annual audit released in April. Information security control weaknesses identified included 13 that remained unresolved from the previous year’s audit, plus 15 new ones, the GAO said. They included insufficient testing and evaluation of controls for a major data system as required by a certification and accreditation process, as well as inconsistent implementation of policies and procedures, including parts of the SEC’s information-security program.

The SEC had corrected 58 of the 71 weaknesses identified in 2005, the GAO noted, and by the completion of its 2006 audit had taken action on 11 of the newly identified faults. But the commission had not adequately guarded identification and authentication of users of data systems, leaving critical information in some instances vulnerable to hacking or unauthorized use or modification, the GAO said. For instance, requests for new or upgraded access to the EDGAR company financial reporting system weren’t always properly reviewed, and records of user privileges didn’t always reflect current information about users’ roles within the SEC.

SPONSORED REPORT

How to make the most of a negotiation

Negotiators are made, not born. In this sponsored report, we cover strategies and tactics to help you head into 2017 ready to take on business deals, salary discussions and more.

VIDEO

Will the Affordable Care Act be repealed?

The results of the 2016 presidential election are likely to have a big impact on federal tax policy in the coming years. Eddie Adkins, CPA, a partner in the Washington National Tax Office at Grant Thornton, discusses what parts of the ACA might survive the repeal of most of the law.

QUIZ

News quiz: Scam email plagues tax professionals—again

Even as the IRS reported on success in reducing tax return identity theft in the 2016 season, the Service also warned tax professionals about yet another email phishing scam. See how much you know about recent news with this short quiz.