U.S. flag

An official website of the United States government Here’s how you know

The .gov means it’s official.

Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you're on a federal government site.

The site is secure.

The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Exportar
Date Issued

Chief Information Officer

  •  
    Status
      Open
      Closed
    2023-OE-0001a-06
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

Public and Indian Housing

  •  
    Status
      Open
      Closed
    2021-OE-0011b-06
    Prioridad
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    PIH in coordination with other HUD offices as necessary, research and address potential causes of the variance in the number of EBLL cases among States on the EBLL tracker and identify solutions that are within HUD's control.


    Status

    On May 7, 2024, the Office of Field Operations (OFO) stated that it met with the Real Estate Assessment Center (REAC) and Office of Lead Hazard Control and Healthy Homes (OLHCHH) on March 4 and April 23 and agreed that OFO and OLHCHH will review CDC data on counties with the highest prevalence of EBLLs in children for counties whose states that have reported their BLL data to CDC. OFO will review its EBLL tracker to determine reporting rates by the largest public housing authorities in those counties. OLHCHH will assign an analyst to summarize the most recently available prevalence rates based on selected states. Subsequently, OFO will scrutinize public housing authorities within those states to ascertain the reported cases.

    The revised estimated completion date is February 28, 2025.


    Analysis

    To fully address this recommendation, OFO must provide evidence of meetings held and summaries of the research conducted. For example, what was the exchange with OLHCHH, did OFO coordinate with any other offices, and what research was conducted? OFO needs to research potential causes for the variances and determine what HUD could do to address them.

    Alternatively, OFO must establish that there are no solutions within HUD’s control to address any identified causes.

    Implementation of this recommendation will help ensure that EBLL cases are reported and recorded appropriately in the EBLL tracker.

Lead Hazard Control

  •  
    Status
      Open
      Closed
    2021-OE-0011b-01
    Prioridad
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Update HUD regulations, policies, and procedures following the regulatory process required by the amended Lead Safe Housing Rule, in consideration of CDC’s lowered BLRV of 3.5 ug/dL.


    Status

    On June 12, 2024, the Office of Lead Hazard Control and Healthy Homes informed HUD OIG that the draft Federal Register notice of its request for information from Lead Safe Housing Rule stakeholders and the general public on its proposal to adopt CDC's BLRV of 3.5 µg/dL as its EBLL under the rule has been circulated for OGC and preclearance review, which will be followed by Departmental clearance. OLHCHH plans on publishing the Federal Register notice by June 30, 2024, with a 60-day comment period. OLHCHH will provide the link and the link and the notice once it is published. OLHCHH will then review public comments in preparing to decide whether to change the rule's current level, and if so, to what level.

    The Office of Lead Hazard Control and Healthy Homes estimated this will be completed by June 30, 2024.


    Analysis

    To fully address this recommendation, OLHCHH must provide evidence that it has updated its regulations, policies, and procedures so that they are consistent with CDC’s lowered BLRV of 3.5 ug/dL.

    Alternatively, OLHCHH must establish that its research led it to determine that environmental interventions in cases of children with EBLLs between 3.5 and 4.9 µg/dL were ineffective in reducing the children’s blood lead levels and that lowering HUD’s EBLL regulation to 3.5 µg/dL is unnecessary.

    Implementation of this recommendation will help ensure children living in public housing with EBLLs receive effective environmental interventions.

Chief Information Officer

  •  
    Status
      Open
      Closed
    2021-OE-0007-01

    Identify short- and long-term plans for the RPA program that align its capabilities, staffing needs, funding projections, and mission needs.

  •  
    Status
      Open
      Closed
    2021-OE-0007-02

    Implement procedures to capture and monitor centralized logs to maintain appropriate visibility into bot activities and provide for auditability of bot actions.

  •  
    Status
      Open
      Closed
    2021-OE-0007-03

    Implement procedures to periodically review RPA system access and remove access for users that are not authorized or no longer have a need to use the system.

  •  
    Status
      Open
      Closed
    2021-OE-0007-04

    Implement procedures to ensure that attended bots use the security rights and credentials of the attending user.

Chief Information Officer

  •  
    Status
      Open
      Closed
    2022-OE-0001-01

    HUD OCIO should implement procedures to ensure that information in cybersecurity risk registers is obtained accurately, consistently, and in a reproducible format and is used to a. quantify and aggregate security risks, b. normalize cybersecurity risk information across organizational units, and c. prioritize operational risk response (derived from metric 5).

  •  
    Status
      Open
      Closed
    2022-OE-0001-02

    HUD OCIO and the HUD Chief Risk Officer should coordinate to implement procedures to monitor the effectiveness of cybersecurity risk responses to ensure that risk tolerances are maintained at an appropriate level (derived from metric 5).

  •  
    Status
      Open
      Closed
    2022-OE-0001-03

    HUD OCIO and the Office of Administration should implement procedures to ensure proper validation of media sanitization in accordance with HUD Media Protection Procedures 2.0 (February 2022) and form HUD 1067A, Certification of Sanitization (derived from metric 36).

  •  
    Status
      Open
      Closed
    2022-OE-0001-04
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

Chief Information Officer

  •  
    Status
      Open
      Closed
    2021-OE-0001-01
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2021-OE-0001-02
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2021-OE-0001-03
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2021-OE-0001-04
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2021-OE-0001-05
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2021-OE-0001-08
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    Prioridad
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Define and communicate policies and procedures to ensure that its products, system components, systems, and services comply with its cybersecurity and SCRM requirements. This recommendation includes:

    • Identification and prioritization of externally provided systems (new and legacy), components, and services.
    • How HUD maintains awareness of its upstream suppliers.
    • The integration of acquisition processes tools, and techniques to use the acquisition process to protect the supply chain.
    • Contract tools or procurement methods to confirm that contractors are meeting their obligations (derived from OIG FISMA metric 14).

    Status

    In May 2024, HUD OIG reviewed the Office of the Chief Information Officer’s progress is closing this recommendation as part of the annual FY 2024 FISMA evaluation. At that time, HUD provided additional evidence in the form of draft SCRM Policy, SCRM Procedures, SCRMES Charter, and a SCRM Technical Roadmap. Additionally, HUD provided agency-specific clauses. At the time, the guidance had not yet been finalized.


    Analysis

    To fully address this recommendation, HUD must establish that it has defined and communicated policies and procedures to ensure that its products, system components, systems, and services comply with its cybersecurity and SCRM requirements. Implementation of this recommendation will result in HUD continuing to mature in supply chain risk management, establishing and defining the policies and procedures of SCRM requirements as it relates to systems and system components.

  •  
    Status
      Open
      Closed
    2021-OE-0001-09
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2021-OE-0001-10
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2021-OE-0001-11
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.