Provide adequate documentation to support its administrative and project delivery cost expenditures or repay the program $1,388,545 from non-Federal funds.
2021-LA-1002 | Enero 05, 2021
Neighborhood Housing Services of Los Angeles County, Los Angeles, CA, Did Not Always Follow Program Requirements in Administering Its NSP2
Community Planning and Development
2021-LA-1002-002-A
$1,388,545Questioned CostsRecommendations with questioned costs identify costs: (A) resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B) that are not supported by adequate documentation (also known as an unsupported cost); or (C) that appear unnecessary or unreasonable.
2021-LA-1002-002-B
$324,478Funds Put to Better UseRecommendations that funds be put to better use estimate funds that could be used more efficiently. For example, recommendations that funds be put to better use could result in reductions in spending, deobligation of funds, or avoidance of unnecessary spending.
Provide supporting documentation to show whether the outstanding liability of $324,478 is correctly classified as an NSP2 liability. If not, HUD should ensure that NHSLA corrects its NSP2 cost reimbursement summary for the 12 months ending June 30, 2018, to reclassify the expenses to a non-NSP2 program. Such funds would be considered funds to be put to better use.
2021-LA-1002-002-C
Develop and implement a HUD-approved cost allocation plan to properly account for indirect program costs.
2021-LA-1002-002-D
Establish written payroll policies and procedures in accordance with program requirements for the tracking, recording, and maintenance of direct costs to ensure that time distribution records are in place to support the allocation of charges.
2021-LA-1002-002-E
Obtain training to ensure that it understands NSP2 regulations and requirements related to payroll allocation for its administrative and project delivery costs and program income calculation methodology to ensure it properly computes the amount it is allowed to charge for administrative costs.
2021-LA-1002-003-A
$856,692Questioned CostsRecommendations with questioned costs identify costs: (A) resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B) that are not supported by adequate documentation (also known as an unsupported cost); or (C) that appear unnecessary or unreasonable.
Support the reasonableness of the South Gate contract or repay NSP2 $856,692 from non-Federal funds.
2021-LA-1002-003-B
Develop and implement additional procedures and controls to ensure that HUD procurement requirements are followed.
2020-OE-0001 | Noviembre 30, 2020
HUD Fiscal Year 2020 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation Report
Chief Information Officer
2020-OE-0001-01
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
PrioridadPriorityWe believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Implement a software asset management capability for software and operating systems to ensure that software executes only from the authorized software inventory and all unauthorized software is blocked from executing on HUD's network.
Status
In April 2024, the Office of the Chief Information Officer reported that it was in the process of implementing a software management tool that would allow it to control which software is authorized to access the network. This is the first step to create rules for allowing only authorized software to be used through HUD's endpoint security software. Final implementation of this new tool is expected by Quarter 2 of FY 2025.
Analysis
To fully address this recommendation, HUD must provide evidence that it has an automated whitelist and implement as per the NIST Special Publication 800-167 or accept the risk and document mitigating measures via a Risk Based Decision memorandum.
Implementation of this recommendation will result in HUD having the capability to ensure only authorized software is used on HUD’s network based on its software asset listing.
2020-OE-0001-02
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2020-OE-0001-03
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2020-OE-0001-07
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2020-OE-0001-09
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2020-OE-0001-13
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2020-OE-0001-15
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
PrioridadPriorityWe believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Implement multifactor authentication mechanisms for all nonprivileged users who access information systems that process, store, or transmit PII.
Status
In April 2024, the Office of the Chief Information Officer reported that it has implemented a new software security solution to implement multifactor authentication, had completed 9 of 15 systems within the first phase, and will be delayed in completing the final system until the last quarter of FY 2024.
Analysis
Implementation of this recommendation will result in an enterprise-wide identity and access management solution which addresses the requirements in Executive Order 14028, titled “Improving the Nation’s Cybersecurity”. Users will be required to use multifactor authentication methods to access HUD data, networks, and devices.
2020-OE-0001-16
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
PrioridadPriorityWe believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Implement multifactor authentication mechanisms for all privileged users who access information systems that process, store, or transmit PII.
Status
In April 2024, the Office of the Chief Information Officer reported that it has implemented a new software security solution to implement multifactor authentication, had completed 9 of 15 systems within the first phase, and will be delayed in completing the final system until the last quarter of FY 2024.
Analysis
Implementation of this recommendation will result in an enterprise-wide identity and access management solution which addresses the requirements in Executive Order 14028, titled “Improving the Nation’s Cybersecurity”. Users will be required to use multifactor authentication methods to access HUD data, networks, and devices.
2020-OE-0001-23
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-LA-1001 | Octubre 27, 2020
The City of Compton, Compton, CA, Did Not Always Administer Neighborhood Stabilization Program Funds in Compliance With Procedures and Regulations
Community Planning and Development
2021-LA-1001-001-A
Implement its procurement controls to ensure that it is able to locate and maintain the complete procurement documents for at least 3 years after the closeout of NSP1 and NSP3 in compliance with its own procedures and HUD regulations.
2021-LA-1001-002-A
$270,656Questioned CostsRecommendations with questioned costs identify costs: (A) resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B) that are not supported by adequate documentation (also known as an unsupported cost); or (C) that appear unnecessary or unreasonable.
Provide the required documents to support $161,131 in NSP1 and $109,525 in NSP3 funds for expenses for acquisition, rehabilitation, and administration. If the City cannot provide the required documents, it should repay the U.S. Treasury from non-Federal funds.
2021-LA-1001-002-B
$1,550Questioned CostsRecommendations with questioned costs identify costs: (A) resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B) that are not supported by adequate documentation (also known as an unsupported cost); or (C) that appear unnecessary or unreasonable.
Repay the U.S. Treasury from non-Federal funds for the $1,550 overpaid to acquire a foreclosed NSP3 property.
2021-LA-1001-002-C
Obtain technical assistance from HUD to ensure that it is able to manage the programs and comply with program regulations before processing future expenses related to NSP1 and NSP3 projects and activities.