For the MF-RAP, PIH-TRA, and CPD-HIM programs, ensure that the program's improper payments rate estimates adequately test for and include improper payments of Federal funding that are made by State, local, and other organizations administering these programs and adequately disclose any limitations imposed or encountered when reporting on improper payments, to a degree that fairly informs users of the respective reported information.
2021-AT-0002 | May 17, 2021
HUD Did Not Fully Comply With the Payment Integrity Information Act of 2019
Chief Financial Officer
- Status2021-AT-0002-001-AOpenClosed
2021-LA-1002 | January 05, 2021
Neighborhood Housing Services of Los Angeles County, Los Angeles, CA, Did Not Always Follow Program Requirements in Administering Its NSP2
Community Planning and Development
- Status2021-LA-1002-001-AOpenClosed$3,425,679Questioned Costs
Recommendations with questioned costs identify costs: (A) resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B) that are not supported by adequate documentation (also known as an unsupported cost); or (C) that appear unnecessary or unreasonable.
Provide documentation to support that program activities within NHSLA’s interfund were for eligible NSP2 activities or repay the program $3,425,679 from non-Federal funds.
- Status2021-LA-1002-001-BOpenClosed$529,745Funds Put to Better Use
Recommendations that funds be put to better use estimate funds that could be used more efficiently. For example, recommendations that funds be put to better use could result in reductions in spending, deobligation of funds, or avoidance of unnecessary spending.
Return the outstanding balance of $529,745 owed to NSP2. In addition, cease the practice of depositing NSP2 funds in non-NSP2 accounts and making them available to be used or borrowed for non-NSP2 activities.
- Status2021-LA-1002-001-COpenClosed$658,261Questioned Costs
Recommendations with questioned costs identify costs: (A) resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B) that are not supported by adequate documentation (also known as an unsupported cost); or (C) that appear unnecessary or unreasonable.
Provide documentation to support that $658,261 in loan proceeds was used for an eligible NSP2 activity or property or repay the program from non-Federal funds.
- Status2021-LA-1002-001-DOpenClosed$500,000Questioned Costs
Recommendations with questioned costs identify costs: (A) resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B) that are not supported by adequate documentation (also known as an unsupported cost); or (C) that appear unnecessary or unreasonable.
Provide documentation to support that $500,000 in NSP funds transferred to the revolving loan fund was used for an eligible NSP2 activity or property or repay the program from non-Federal funds.
- Status2021-LA-1002-001-GOpenClosed
Amend the NSP2 action plan to include its revolving loan fund.
- Status2021-LA-1002-001-HOpenClosed
Adjust program income calculation methodology to ensure it is in accordance with HUD requirements.
- Status2021-LA-1002-001-IOpenClosed
Submit overdue NSP2 quarterly reports to DRGR and update prior reports that did not accurately report program income activity.
- Status2021-LA-1002-002-AOpenClosed$1,388,545Questioned Costs
Recommendations with questioned costs identify costs: (A) resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B) that are not supported by adequate documentation (also known as an unsupported cost); or (C) that appear unnecessary or unreasonable.
Provide adequate documentation to support its administrative and project delivery cost expenditures or repay the program $1,388,545 from non-Federal funds.
- Status2021-LA-1002-002-BOpenClosed$324,478Funds Put to Better Use
Recommendations that funds be put to better use estimate funds that could be used more efficiently. For example, recommendations that funds be put to better use could result in reductions in spending, deobligation of funds, or avoidance of unnecessary spending.
Provide supporting documentation to show whether the outstanding liability of $324,478 is correctly classified as an NSP2 liability. If not, HUD should ensure that NHSLA corrects its NSP2 cost reimbursement summary for the 12 months ending June 30, 2018, to reclassify the expenses to a non-NSP2 program. Such funds would be considered funds to be put to better use.
- Status2021-LA-1002-002-EOpenClosed
Obtain training to ensure that it understands NSP2 regulations and requirements related to payroll allocation for its administrative and project delivery costs and program income calculation methodology to ensure it properly computes the amount it is allowed to charge for administrative costs.
- Status2021-LA-1002-003-AOpenClosed$856,692Questioned Costs
Recommendations with questioned costs identify costs: (A) resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B) that are not supported by adequate documentation (also known as an unsupported cost); or (C) that appear unnecessary or unreasonable.
Support the reasonableness of the South Gate contract or repay NSP2 $856,692 from non-Federal funds.
2020-OE-0001 | November 30, 2020
HUD Fiscal Year 2020 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation Report
Chief Information Officer
- Status2020-OE-0001-01OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
PriorityPriorityWe believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Implement a software asset management capability for software and operating systems to ensure that software executes only from the authorized software inventory and all unauthorized software is blocked from executing on HUD's network.
Status
In April 2024, the Office of the Chief Information Officer reported that it was in the process of implementing a software management tool that would allow it to control which software is authorized to access the network. This is the first step to creating rules for allowing only authorized software to be used through HUD's endpoint security software. The final implementation of this new tool is expected by Quarter 2 of FY 2025.
Analysis
To fully address this recommendation, HUD must provide evidence that it has an automated whitelist and it is implemented as per the NIST Special Publication 800-167 or accept the risk and document mitigating measures via a Risk-Based Decision memorandum.
Implementation of this recommendation will result in HUD having the capability to ensure only authorized software is used on HUD’s network based on its software asset listing.
- Status2020-OE-0001-02OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2020-OE-0001-03OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2020-OE-0001-07OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2020-OE-0001-09OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2020-OE-0001-13OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2020-OE-0001-15OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
PriorityPriorityWe believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Implement multifactor authentication mechanisms for all nonprivileged users who access information systems that process, store, or transmit PII.
Status
The Office of the Chief Information Officer reported that it has implemented a new software security solution to implement multifactor authentication, starting with a pilot on 15 FHA systems. In October 2024, HUD received additional funds through the Technology Modernization Fund for this project enterprisewide.
Analysis
To fully address the recommendation, HUD must implement multifactor authentication enterprisewide.
Implementation of this recommendation will result in an enterprise-wide identity and access management solution. Users will be required to use multifactor authentication methods to access HUD data, networks, and devices.
- Status2020-OE-0001-16OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
PriorityPriorityWe believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Implement multifactor authentication mechanisms for all privileged users who access information systems that process, store, or transmit PII.
Status
The Office of the Chief Information Officer reported that it has implemented a new software security solution to implement multifactor authentication, starting with a pilot on 15 FHA systems. In October 2024, HUD received additional funds through the Technology Modernization Fund for this project enterprisewide.
Analysis
To fully address this recommendation, HUD must implement the eICAM plan it developed with the funding it received.
Implementation of this recommendation will result in an enterprise-wide identity and access management solution. Users will be required to use multifactor authentication methods to access HUD data, networks, and devices.