HUD Can Improve Its Efforts To Meet the National Drug Control Strategy Reporting Requirements
The Office of National Drug Control Policy (ONDCP) leads and coordinates the Nation’s drug policy to improve the health and lives of the American people, including the development and implementation of the National Drug Control Strategy (the Strategy). ONDCP evaluates the effectiveness of national drug control policy efforts, the Strategy’s goals and objectives, and each National Drug Control Program Agency’s program-level measures. …
March 17, 2025
Review
#2025-LA-0001
FHA Catalyst Personally Identifiable Information Risk Management in a Zero Trust Environment (2023-OE-0007a) Interim Evaluation Report
The OIG evaluated the U.S. Department of Housing and Urban Development (HUD) Office of Housing’s (Housing) progress in applying zero trust security principles to protect personally identifiable information (PII) within the Federal Housing Administration (FHA) Catalyst system.HUD was in the beginning stages of implementing zero trust requirements for the data and identity pillars. HUD Office of Housing systems, including FHA Catalyst, are largely…
October 31, 2024
Report
#2023-OE-0007a
HUD FY 2024 Federal Information Security Modernization Act (FISMA) Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to assess the…
October 29, 2024
Report
#2024-OE-0002
HUD FY 2023 Federal Information Security Modernization Act (FISMA) Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to assess the…
January 29, 2024
Report
#2023-OE-0001
Preventing Duplication of Benefits When Using Community Development Block Grant Disaster Recover and Mitigation Funds
We performed an audit examining HUD’s efforts to prevent duplication of benefits when using Community Development Block Grant (CDBG) Disaster Recovery and Mitigation funds. Our objective was to determine how the U.S. Department of Housing and Urban Development (HUD) assesses the adequacy of grantee procedures to prevent a duplication of benefits, both before and after grant execution.
HUD certified grantees’ high-level processes for…
October 24, 2023
Report
#2024-FW-0001
HUD’s Robotic Process Automation Program Was Not Efficient or Effective
We conducted this evaluation to assess the maturity of HUD’s Robotic process automation (RPA) activities and determine whether HUD had implemented related controls to address technology and program management risks. RPA is a software technology used to emulate human actions on a computer. RPA software programs, referred to as “bots,” can complete repetitive tasks quickly and consistently, freeing up employees to work on other, higher…
February 17, 2023
Report
#2021-OE-0007
Assessment of HUD’s IT Infrastructure To Support Extensive Telework
We audited the U.S. Department of Housing and Urban Development’s (HUD) information technology (IT) infrastructure to support mandatory telework. During mandatory telework, more employees simultaneously needed remote access to HUD’s network and agency resources for an extended period, which presented unique risks and security requirements. While HUD is no longer operating under mandatory telework, understanding the challenges it faced is key to…
January 24, 2023
Report
#2023-FO-0008
Management Alert: Action Needed to Ensure That Assisted Property Owners, Including Public Housing Agencies, Comply with the Lead Safe Housing Rule
While conducting an ongoing audit of the Philadelphia Housing Authority’s (Authority) management of lead-based paint hazards in its public housing units, we identified a significant gap in HUD’s program requirements related to safe work practices, which we believe requires immediate action by HUD. We identified that the Authority determined a substantial percentage of maintenance and hazard reduction work performed on surfaces with lead-…
October 04, 2022
Report
#2023-IG-0001
HUD FY 2022 Federal Information Security Modernization Act (FISMA) Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to assess…
September 30, 2022
Report
#2022-OE-0001
Geospatial Data Act of 2018, Fiscal Year 2022
We audited the U.S. Department of Housing and Urban Development’s (HUD) efforts to meet the Geospatial Data Act of 2018 (the Act).Our audit objective was to determine whether HUD met the 13 responsibilities stated in the Act with regard to its collection, production, acquisition, maintenance, distribution, use, and preservation of geospatial data. The Act also generally requires covered agencies provide access to geospatial data and…
September 30, 2022
Report
#2022-LA-0004
Fiscal Year 2021 Federal Information Security Modernization Act (FISMA) Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to assess…
February 17, 2022
Report
#2021-OE-0001
Fiscal Year 2021 Federal Information Security Modernization Act (FISMA) Evaluation Security Technical Testing Topic Brief
The Federal Information Security Modernization Act of 2014 (FISMA) requires all federal agencies to conduct independent security technical verification testing on a sampling of information systems annually. In conjunction with our fiscal year 2021 FISMA evaluation (2021-OE-0001), we conducted a targeted security testing assessment of sample systems that resulted in a Topic Brief. The objective of this application vulnerability…
February 15, 2022
Topic brief
#2021-OE-0001a
HUD’s Processes for Managing IT Acquisitions
We reviewed the U.S. Department of Housing and Urban Development’s (HUD) ability to effectively complete information technology (IT) acquisitions. HUD’s IT systems and its modernization plans depend heavily on contractors, yet HUD has historically faced significant challenges with implementing effective acquisition processes. Therefore, HUD’s acquisition capacity represents a key potential risk within HUD’s IT environment. We found that a…
November 17, 2021
Report
#2020-OE-0004
Delays in Federal Housing Administration Catalyst’s Development
In February 2021, the Office of the Chief Information Officer (OCIO) identified funding risks with the development contract under which HUD contracted for Federal Housing Administration (FHA) Catalyst’s development. In response, HUD officials took steps to slow FHA Catalyst spending on the contract while awaiting approval for additional contract funds. Despite efforts to slow project spending, it was not enough to prevent funding…
November 17, 2021
Memorandum
#2021-OE-0003a
2021 Persistent IT Challenges and Issues Facing HUD
The brief provides an update to the original 2018 topic brief, and highlights key challenges faced by HUD in managing and improving its IT program. The brief is not based on new work, but is a summary of 83 reports and 788 recommendations from past HUD OIG and GAO reports. It discusses the present IT environment at HUD, previously identified and new IT-related challenges, and HUD’s efforts and progress in addressing these challenges.…
August 09, 2021
Topic brief
#2021-OE-0004
HUD IT Modernization Roadmap Evaluation Report
We reviewed the U.S. Department of Housing and Urban Development’s (HUD) information technology (IT) modernization roadmap. A significant number of HUD’s mission-essential applications have not been modernized, which presents multiple sources of risk. These applications are hosted on legacy information systems and mainframe platforms, which are operationally inefficient, increasingly difficult to secure, and costly to maintain.…
June 29, 2021
Report
#2021-OE-0003
HUD Program Offices’ Policies and Approaches for Radon
HUD does not have a departmentwide policy for dealing with radon contamination. Instead, HUD relies on each program office to develop radon policies that align with HUD’s environmental regulations. The three program offices reviewed do not have consistent radon policies. Only Multifamily’s radon policy includes radon testing and mitigation requirements. PIH’s policy strongly encourages but does not require public housing…
April 12, 2021
Report
#2020-OE-0003
Fiscal Year 2019 Review of Information Systems Controls in Support of the Financial Statements Audit
We audited information systems controls over the U.S. Department of Housing and Urban Development’s (HUD) computing environment as part of the internal control assessments for the fiscal year 2019 financial statements audit under the Chief Financial Officer’s Act of 1990. Our objective was to assess general controls over HUD’s computing environment for compliance with HUD information technology policies and Federal information system security…
December 17, 2020
Report
#2021-DP-0001
HUD Fiscal Year 2020 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to assess…
November 30, 2020
Report
#2020-OE-0001
HUD Had Implemented Most of the Required Responsibilities Stated in the Geospatial Data Act of 2018
We audited the U.S. Department of Housing and Urban Development’s (HUD) Office of Policy Development and Research’s implementation of the responsibilities stated in the Geospatial Data Act of 2018 (The Act). We performed this review in response to a congressional mandate that HUD’s geospatial data be audited at least once every 2 years. The Act requires that we audit HUD’s collection, production, acquisition, maintenance,…
September 24, 2020
Report
#2020-LA-0002