Skip to main content
All frameworks

IRS Publication 1075 Automation

IRS 1075 safeguards,evidenced before the Safeguard review.

Agencies and contractors that receive federal tax information must meet IRS Publication 1075's NIST 800-53 based safeguards. CISGuard automates the technical configuration evidence Safeguard reviews examine.

United StatesState and Local Government Agencies, Contractors Handling FTI
Authority
IRC Section 6103 confidentiality; enforced by the IRS Office of Safeguards
Applies to
Federal, state, and local agencies plus contractors handling FTI
Control basis
Security requirements derived from NIST SP 800-53
Oversight
Safeguard reviews + annual Safeguard Security Report (SSR)
Stakes
Findings can jeopardize continued access to FTI
CISGuard NIST mapping
50 NIST 800-53 controls across 13 families, reused for Pub 1075 evidence

Overview

What is IRS 1075?

IRS Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies, defines the safeguards required of any agency or contractor that receives federal tax information (FTI) from the IRS. Its legal foundation is Internal Revenue Code Section 6103, which makes tax returns and return information confidential and conditions disclosure on adequate protection. Publication 1075 derives its security control requirements from NIST SP 800-53, applying them to every system that receives, processes, stores, or transmits FTI. Compliance is actively enforced: the IRS Office of Safeguards conducts on-site Safeguard reviews, and agencies must file an annual Safeguard Security Report describing how FTI is protected. Findings can jeopardize an agency's continued access to FTI. The technical core of a Safeguard review is configuration: access control, audit logging, hardening, and patch state on FTI systems. Those are the controls CISGuard evidences continuously through CIS benchmark scanning, mapped to the NIST 800-53 control families Publication 1075 draws from.

How CISGuard automates IRS 1075 evidence

Because Publication 1075 builds its safeguarding requirements on NIST SP 800-53, CISGuard's existing NIST mapping does double duty: the 50 mapped 800-53 controls across 13 families become the technical evidence base for FTI systems. Every server and workstation in the FTI boundary is scanned continuously against CIS Benchmarks, producing per-control pass/fail results for access control, audit logging, hardening, authentication, and patch state, exactly the configuration territory Safeguard reviewers test. Drift detection documents that hardened configurations stayed hardened between reviews, and the historical posture trends give the annual Safeguard Security Report a factual configuration narrative instead of assertions. When the Office of Safeguards schedules a review, the Framework Coverage Report presents each control family's status with timestamps and underlying scan data. Government agencies frequently run FTI systems in restricted enclaves; CISGuard deploys fully on-premises or air-gapped, so FTI system configuration data never leaves the boundary. CISGuard is not affiliated with the IRS and does not determine compliance; it supplies the technical evidence your safeguards program and reviewers rely on.

Control mapping

Publication 1075 control areas CISGuard automates.

Each CIS control is tagged with its framework reference. One scan produces the per-framework coverage report, with satisfied, partially satisfied and not-met status for every control.

Control areaControlsMapped by
Access control for FTI systemsPub 1075 requirements based on the NIST 800-53 AC familyCIS Account + Privilege Management benchmarks
Audit and accountabilityPub 1075 requirements based on the NIST 800-53 AU familyCIS Audit Policy benchmarks (Windows + Linux)
Configuration managementPub 1075 requirements based on the NIST 800-53 CM familyContinuous CIS benchmark scanning + drift detection
Identification and authenticationPub 1075 requirements based on the NIST 800-53 IA familyCIS Password Policy + authentication benchmarks
System and communications protectionPub 1075 requirements based on the NIST 800-53 SC familyCIS Network + Cryptography benchmarks
System and information integrityPub 1075 requirements based on the NIST 800-53 SI familyCIS Update + Anti-malware benchmarks

Auditor evidence

Evidence artifacts CISGuard generates.

Auditor-grade outputs in PDF, HTML, JSON, CSV and SARIF. No spreadsheets, no screenshots, no manual cross-referencing.

  • NIST 800-53 Framework Coverage Report scoped to FTI boundary systems
  • Per-control pass/fail results with timestamps across AC, AU, CM, IA, SC, SI families
  • Drift detection history showing configurations held between Safeguard reviews
  • Audit logging configuration evidence for FTI access accountability
  • Patch and update posture reports for FTI systems
  • Posture trend history supporting the annual Safeguard Security Report

Frequently asked

IRS 1075 questions, answered directly.

Who must comply with IRS Publication 1075?

Any federal, state, or local agency that receives federal tax information from the IRS, and any contractor or subcontractor those agencies authorize to handle FTI. Common examples include state departments of revenue, child support enforcement, and human services agencies, plus their IT service providers. The obligation follows the data: every system that receives, processes, stores, or transmits FTI is in scope.

How does Publication 1075 relate to NIST 800-53?

Publication 1075 derives its security control requirements from NIST SP 800-53, applying them to systems handling FTI. That is good news for automation: CISGuard already maps 50 NIST 800-53 controls across 13 families to CIS benchmark scans, so the same continuous evidence base serves Pub 1075. Agencies already aligned to 800-53 for other programs reuse most of that work.

What is an IRS Safeguard review?

A review conducted by the IRS Office of Safeguards to verify that an agency protects FTI as Publication 1075 requires. Reviews examine physical, administrative, and technical safeguards, and technical findings often center on configuration: access control, audit logging, hardening, and patching on FTI systems. Findings must be remediated and can jeopardize continued FTI access. CISGuard's continuous scans document exactly that configuration state in advance.

Can CISGuard run inside a restricted FTI enclave?

Yes. CISGuard deploys fully on-premises and supports air-gapped operation, so scanning, evidence storage, and reporting stay inside the FTI boundary with no outbound data path. That fits the isolation posture many agencies apply to FTI systems. Reports for the Safeguard Security Report or a review are exported deliberately, under your control, rather than through any cloud dependency.

Does CISGuard certify our agency as Pub 1075 compliant?

No. Compliance determinations belong to the IRS Office of Safeguards, and your agency remains responsible for its safeguards program. CISGuard supplies the continuous technical evidence underneath: CIS benchmark scan results mapped to the NIST 800-53 control families Publication 1075 draws from, drift history, and per-system configuration reports that support your SSR and stand up to review scrutiny.

IRS 1075 readiness, on request.

Our compliance engineers have helped organizations achieve regulatory readiness through a seamless, fully managed deployment.