HUD OCIO should define and implement metrics to monitor the effectiveness of ICAM program activities and assist in identifying areas for improvement (IG FISMA metric 26).
2023-OE-0001 | January 29, 2024
HUD FY 2023 Federal Information Security Modernization Act (FISMA) Evaluation Report
Chief Information Officer
- Status2023-OE-0001-11OpenClosed
- Status2023-OE-0001-12OpenClosed
HUD OCIO should develop a comprehensive ICAM policy, strategy, process, and technology solution roadmap, including milestones, budget estimates, and appropriate technology solution details (IG FISMA metric 27). This recommendation replaces FY 2020 FISMA recommendation 11.
- Status2023-OE-0001-13OpenClosed
HUD OCIO should define policies and guidance for the use of system-specific access agreements (IG FISMA metric 29).
- Status2023-OE-0001-14OpenClosed
HUD OCIO should develop a plan that includes milestones and funding requirements for implementing phishing-resistant MFA for all users in alignment with Federal requirements (IG FISMA metrics 30 and 31).
- Status2023-OE-0001-15OpenClosed
HUD OCIO, in coordination with other appropriate HUD offices, should define and communicate policies and procedures for use of MFA at HUD facilities (IG FISMA metrics 30 and 31).
- Status2023-OE-0001-16OpenClosed
HUD OCIO should implement procedures to ensure that digital identity risk assessments have been performed and documented in accordance with HUD’s defined procedures and Federal guidelines (IG FISMA metrics 30 and 31).
- Status2023-OE-0001-17OpenClosed
HUD OCIO should define a plan to meet the logging requirements at all event logging maturity levels (basic, intermediate, advanced) in accordance with OMB M-21-31. This plan should include logging sufficient to allow for reviewing privileged user activities (IG FISMA metrics 32 and 54).
- Status2023-OE-0001-18OpenClosed
HUD OCIO should develop and implement monitoring and enforcement procedures to ensure that non-GFE devices (for example, BYOD), such as those owned by contractors or HUD employees, are either: (a) prohibited from connecting to the HUD network; or (b) properly authorized and configured before connection to the HUD network (IG FISMA metrics 2, 21, and 33).
- Status2023-OE-0001-19OpenClosed
HUD OCIO should develop and implement procedures and contract terms to enforce forfeiture of non-GFE devices (for example, BYOD), to allow for analysis when security incidents occur (IG FISMA metrics 33 and 55).
- Status2023-OE-0001-21OpenClosed
HUD OCIO should develop and implement processes to monitor and analyze qualitative and quantitative performance measures for the effectiveness of its ISCM program (IG FISMA metric 47).
- Status2023-OE-0001-22OpenClosed
HUD OCIO should define a process and assign responsibility to evaluate the effectiveness of its incident response technologies and adjust configurations and toolsets to improve the incident response program (IG FISMA metric 58).
- Status2023-OE-0001-23OpenClosed
HUD OCIO should update its enterprisewide business impact prioritization analysis procedures to include system dependencies and the characterization of system components (IG FISMA metric 61).
2023-OE-0001a | December 20, 2023
Fiscal Year 2023 Federal Information Security Modernization Act of 2014 Penetration Test Evaluation Report
Chief Information Officer
- Status2023-OE-0001a-01OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-02OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-03OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-05OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-06OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2023-LA-0005 | July 28, 2023
HUD’s Assistance and Grantee Challenges With the Office of Native American Programs’ COVID-19 Recovery Programs
Public and Indian Housing
- Status2023-LA-0005-001-AOpenClosed
Consider grantee feedback on the challenges they faced as part of ONAP’s planning for technical assistance and training of ONAP COVID-19 recovery program grantees.
2023-CH-0004 | May 30, 2023
HUD Can Improve Its Oversight of the Physical Condition of Public Housing Developments
Public and Indian Housing
- Status2023-CH-0004-001-AOpenClosedPriorityPriority
We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Develop and implement a nationwide inspection review protocol, which includes but is not limited to (1) whether field office staff should mark verification of PHA corrections of life-threatening deficiencies in PASS or any future tracking systems, (2) acceptable documentation for offsite verifications, and (3) whether field office staff should discuss or verify corrections of non-life-threatening deficiencies.
Corrective Action Taken
HUD's Office of Field Operations (OFO) created a protocol describing how it would perform quality control reviews of field office oversight of PHAs’ corrections of life-threatening deficiencies. The implementation of this recommendation resulted in HUD creating a protocol that established consistency in the way HUD field office staff monitored public housing agencies’ corrections of life-threatening deficiencies.
- Status2023-CH-0004-001-BOpenClosedPriorityPriority
We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Develop and implement training for field offices that addresses reviewing or following up with PHAs about the correction of life-threatening and non-life-threatening deficiencies and how (1) to review physical inspection reports to effectively ensure that PHAs correct physical deficiencies, (2) PHAs should address or correct each type of deficiency observed in the REAC physical inspection report, and (3) to use PASS or any future tracking system.
Corrective Action Taken
HUD developed and provided training to the field offices on their roles and responsibilities for following up with PHAs on the correction of life-threatening and non-life-threatening deficiencies observed during REAC inspections, the NSPIRE system and standards, protocols, and timelines for deficiency correction and verification. Implementation of the recommendation will help HUD to ensure that field office staff are clear on their roles and responsibilities to communicate with PHAs on how deficiencies should be addressed and verify that PHAs’ inspection deficiencies have been corrected.