The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-OE-0001 | Febrero 17, 2022
Fiscal Year 2021 Federal Information Security Modernization Act (FISMA) Evaluation Report
Chief Information Officer
2021-OE-0001-03
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
2021-OE-0001-04
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-OE-0001-05
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-OE-0001-08
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
PrioridadPriorityWe believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Define and communicate policies and procedures to ensure that its products, system components, systems, and services comply with its cybersecurity and SCRM requirements. This recommendation includes:
- Identification and prioritization of externally provided systems (new and legacy), components, and services.
- How HUD maintains awareness of its upstream suppliers.
- The integration of acquisition processes tools, and techniques to use the acquisition process to protect the supply chain.
- Contract tools or procurement methods to confirm that contractors are meeting their obligations (derived from OIG FISMA metric 14).
Status
In May 2024, HUD OIG reviewed the Office of the Chief Information Officer’s progress is closing this recommendation as part of the annual FY 2024 FISMA evaluation. At that time, HUD provided additional evidence in the form of draft SCRM Policy, SCRM Procedures, SCRMES Charter, and a SCRM Technical Roadmap. Additionally, HUD provided agency-specific clauses. At the time, the guidance had not yet been finalized.
Analysis
To fully address this recommendation, HUD must establish that it has defined and communicated policies and procedures to ensure that its products, system components, systems, and services comply with its cybersecurity and SCRM requirements. Implementation of this recommendation will result in HUD continuing to mature in supply chain risk management, establishing and defining the policies and procedures of SCRM requirements as it relates to systems and system components.
2021-OE-0001-09
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-OE-0001-10
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-OE-0001-11
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-OE-0001-13
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-OE-0001-14
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-OE-0001-15
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-OE-0001-16
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-OE-0001-20
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-OE-0001-21
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-OE-0001-22
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2022-BO-0001 | Febrero 07, 2022
HUD Did Not Have Adequate Policies and Procedures for Ensuring That Public Housing Agencies Properly Processed Requests for Reasonable Accommodation
Public and Indian Housing
2022-BO-0001-001-B
We recommend that HUD’s Deputy Assistant Secretary for Public Housing and Voucher Programs update and consolidate requests for reasonable accommodation policies and procedures to ensure that there is centralized guidance available for the field offices and PHAs.
2022-BO-0001-001-C
We recommend that HUD’s Deputy Assistant Secretary for Public Housing and Voucher Programs conduct additional outreach efforts to educate tenants and PHAs on their rights and responsibilities related to requests for reasonable accommodation, including technical assistance, webinars, and external communications to inform PHAs about their responsibilities and how to evaluate requests for reasonable accommodation, and help families understand their rights.
2022-BO-0001-001-D
We recommend that HUD’s Deputy Assistant Secretary for Public Housing and Voucher Programs require that PHAs track requests for reasonable accommodation, including the date of the request, the type of request, and the disposition and date of any action taken that should be made available to HUD at its request.
2022-LA-1001 | Enero 20, 2022
The Los Angeles Homeless Services Authority, Los Angeles, CA, Did Not Always Administer Its Continuum of Care Program in Accordance With HUD Requirements
Community Planning and Development
2022-LA-1001-001-A
$3,500,000Funds Put to Better UseRecommendations that funds be put to better use estimate funds that could be used more efficiently. For example, recommendations that funds be put to better use could result in reductions in spending, deobligation of funds, or avoidance of unnecessary spending.
Develop and implement policies and procedures to ensure that subgrantee agreements are executed in a timely manner, effective monitoring is performed, and subgrantees maintain an emphasis on using their CoC funds, thereby preventing similar occurrences of $3.5 million (see appendix D) in CoC funding going unused.
2022-LA-1001-002-A
$824,302Questioned CostsRecommendations with questioned costs identify costs: (A) resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B) that are not supported by adequate documentation (also known as an unsupported cost); or (C) that appear unnecessary or unreasonable.
Adequately support the eligibility of payroll costs or repay its CoC grants $824,302 from non-Federal funds.
2022-LA-1001-002-B
$55,545Questioned CostsRecommendations with questioned costs identify costs: (A) resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B) that are not supported by adequate documentation (also known as an unsupported cost); or (C) that appear unnecessary or unreasonable.
Adequately support the eligibility of rent costs or repay its CoC grants $55,545 from non-Federal funds.