U.S. flag

An official website of the United States government Here’s how you know

The .gov means it’s official.

Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you're on a federal government site.

The site is secure.

The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Export
Date Issued

Chief Information Officer

  •  
    Status
      Open
      Closed
    2023-OE-0001-11

    HUD OCIO should define and implement metrics to monitor the effectiveness of ICAM program activities and assist in identifying areas for improvement (IG FISMA metric 26).

  •  
    Status
      Open
      Closed
    2023-OE-0001-12

    HUD OCIO should develop a comprehensive ICAM policy, strategy, process, and technology solution roadmap, including milestones, budget estimates, and appropriate technology solution details (IG FISMA metric 27). This recommendation replaces FY 2020 FISMA recommendation 11.

  •  
    Status
      Open
      Closed
    2023-OE-0001-13

    HUD OCIO should define policies and guidance for the use of system-specific access agreements (IG FISMA metric 29).

  •  
    Status
      Open
      Closed
    2023-OE-0001-14

    HUD OCIO should develop a plan that includes milestones and funding requirements for implementing phishing-resistant MFA for all users in alignment with Federal requirements (IG FISMA metrics 30 and 31).

  •  
    Status
      Open
      Closed
    2023-OE-0001-15

    HUD OCIO, in coordination with other appropriate HUD offices, should define and communicate policies and procedures for use of MFA at HUD facilities (IG FISMA metrics 30 and 31).

  •  
    Status
      Open
      Closed
    2023-OE-0001-16

    HUD OCIO should implement procedures to ensure that digital identity risk assessments have been performed and documented in accordance with HUD’s defined procedures and Federal guidelines (IG FISMA metrics 30 and 31).

  •  
    Status
      Open
      Closed
    2023-OE-0001-17

    HUD OCIO should define a plan to meet the logging requirements at all event logging maturity levels (basic, intermediate, advanced) in accordance with OMB M-21-31. This plan should include logging sufficient to allow for reviewing privileged user activities (IG FISMA metrics 32 and 54).

  •  
    Status
      Open
      Closed
    2023-OE-0001-18

    HUD OCIO should develop and implement monitoring and enforcement procedures to ensure that non-GFE devices (for example, BYOD), such as those owned by contractors or HUD employees, are either: (a) prohibited from connecting to the HUD network; or (b) properly authorized and configured before connection to the HUD network (IG FISMA metrics 2, 21, and 33).

  •  
    Status
      Open
      Closed
    2023-OE-0001-19

    HUD OCIO should develop and implement procedures and contract terms to enforce forfeiture of non-GFE devices (for example, BYOD), to allow for analysis when security incidents occur (IG FISMA metrics 33 and 55).

  •  
    Status
      Open
      Closed
    2023-OE-0001-21

    HUD OCIO should develop and implement processes to monitor and analyze qualitative and quantitative performance measures for the effectiveness of its ISCM program (IG FISMA metric 47).

  •  
    Status
      Open
      Closed
    2023-OE-0001-22

    HUD OCIO should define a process and assign responsibility to evaluate the effectiveness of its incident response technologies and adjust configurations and toolsets to improve the incident response program (IG FISMA metric 58).

  •  
    Status
      Open
      Closed
    2023-OE-0001-23

    HUD OCIO should update its enterprisewide business impact prioritization analysis procedures to include system dependencies and the characterization of system components (IG FISMA metric 61).

Chief Information Officer

  •  
    Status
      Open
      Closed
    2023-OE-0001a-01
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2023-OE-0001a-02
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2023-OE-0001a-03
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2023-OE-0001a-05
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2023-OE-0001a-06
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

Community Planning and Development

  •  
    Status
      Open
      Closed
    2024-FW-0002-001-A

    We recommend that the Director of Disaster Recovery collect and record the number of days that it or other entities take to complete each milestone in the grant process.

  •  
    Status
      Open
      Closed
    2024-FW-0002-001-B

    We recommend that the Director of Disaster Recovery establish timing benchmarks for the milestones at each significant step in the allocation and award process based on actual data accumulated for the various grants.

  •  
    Status
      Open
      Closed
    2024-FW-0002-001-C

    We recommend that the Director of Disaster Recovery take steps to ensure that the milestone point of allocation is formally defined and documented, to allow for accurate tracking of compliance with requirements.