The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2019-OE-0002 | Junio 25, 2020
HUD Fiscal Year 2019 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation Report
Chief Information Officer
- Status2019-OE-0002-12OpenClosedClosed on Octubre 01, 2021SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
- Status2019-OE-0002-13OpenClosedClosed on Noviembre 18, 2021SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2019-OE-0002-14OpenClosedClosed on Agosto 26, 2024SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2019-OE-0002-15OpenClosedClosed on Marzo 10, 2022SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2019-OE-0002-16OpenClosedClosed on Agosto 26, 2024SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
PrioridadPriorityWe believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
HUD Office of the Chief Information Officer (OCIO) should finish developing the procedures for the HUD Security Operations Center (SOC) to monitor all inbound and outbound traffic and all HUD network devices.
Corrective Action Taken
HUD OCIO updated its Cybersecurity Incident Response Plan and developed more detection and protection mechanisms to monitor network traffic in its IT environment. These mechanisms include anti-malware agents, data loss prevention, endpoint detection and response, firewalls, and intrusion detection and prevention systems. HUD’s SOC also developed standard operating procedures and playbooks for abnormal traffic alerts triggered by the above tools that are posted internally for SOC personnel to utilize. Addressing this recommendation resulted in improvement of HUD’s networking monitoring process by enhancing visibility into network traffic. It also increased HUD’s incident response program capabilities by ensuring that HUD has a plan to monitor traffic and better detect and respond to security incidents. As part of our regular Federal Information Security Act of 2014 (FISMA) assessments, HUD OIG will continue to assess HUD’s incident response effectiveness and threat detection to ensure HUD addresses new and evolving threats.
- Status2019-OE-0002-17OpenClosedClosed on Marzo 23, 2021SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2019-OE-0002-18OpenClosedClosed on Julio 19, 2024SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2019-OE-0002-19OpenClosedClosed on Julio 01, 2021SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2019-OE-0002-20OpenClosedClosed on Febrero 10, 2022SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2019-OE-0002-21OpenClosedClosed on Enero 19, 2021SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2019-OE-0002-22OpenClosedClosed on Enero 19, 2021SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2019-OE-0002-23OpenClosedClosed on Diciembre 09, 2021SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2019-OE-0002-24OpenClosedClosed on Agosto 18, 2022SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2019-OE-0002-25OpenClosedClosed on Febrero 10, 2022SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2019-OE-0002-26OpenClosedClosed on Octubre 04, 2022SensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2020-KC-1001 | Junio 08, 2020
Englewood Apartments Did Not Comply With Tenant Eligibility and Recertification Requirements
General Counsel
- Status2020-KC-1001-001-GOpenClosedClosed on Septiembre 17, 2020
Take appropriate administrative action, up to and including debarment, against the owner for the violations cited in this report including, amongst others, failure to perform the required inspections to ensure that the units the owner were billing for assistance were decent, safe, and sanitary.
Housing
- Status2020-KC-1001-001-AOpenClosedClosed on Junio 14, 2021$377,108Questioned Costs
Recommendations with questioned costs identify costs: (A) resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B) that are not supported by adequate documentation (also known as an unsupported cost); or (C) that appear unnecessary or unreasonable.
Require the Englewood Apartments’ owner to repay HUD from non-project funds the projected $377,108 in housing assistance payments for tenants who were not eligible for assistance.
- Status2020-KC-1001-001-BOpenClosedClosed on Junio 14, 2021$24,295Questioned Costs
Recommendations with questioned costs identify costs: (A) resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B) that are not supported by adequate documentation (also known as an unsupported cost); or (C) that appear unnecessary or unreasonable.
Require Englewood Apartments to support that $24,295 in unsupported housing assistance payments was eligible and accurate. Englewood Apartments’ owner should repay any subsidy overpayments to HUD from non-project sources. Further, the owner should reimburse tenants for overcharged rents or enter into a repayment agreement with tenants who were undercharged due to nondisclosure of income.
- Status2020-KC-1001-001-COpenClosedClosed on Abril 08, 2021
Require the Englewood Apartments’ owner to implement appropriate controls, including a formalized process, to use when conducting initial certifications and interim and annual recertifications to ensure that tenants are eligible, housing assistance payments are accurate, and tenant files contain all required documentation to comply with HUD’s and its own requirements. In addition, the updated controls should ensure a layer of management oversight to review all certifications before final approval until such time as onsite management is trained and has been proven to follow HUD’s and its own requirements.
- Status2020-KC-1001-001-DOpenClosedClosed on Marzo 02, 2021
Ensure that the owner, management agent, and staff complete training to ensure that they understand their duties, including HUD’s and local tenant eligibility and certification requirements.