HUD OCIO should implement procedures to ensure that digital identity risk assessments have been performed and documented in accordance with HUD’s defined procedures and Federal guidelines (IG FISMA metrics 30 and 31).
2023-OE-0001 | January 29, 2024
HUD FY 2023 Federal Information Security Modernization Act (FISMA) Evaluation Report
Chief Information Officer
- Status2023-OE-0001-16OpenClosedClosed on August 26, 2024
- Status2023-OE-0001-17OpenClosed
HUD OCIO should define a plan to meet the logging requirements at all event logging maturity levels (basic, intermediate, advanced) in accordance with OMB M-21-31. This plan should include logging sufficient to allow for reviewing privileged user activities (IG FISMA metrics 32 and 54).
- Status2023-OE-0001-18OpenClosed
HUD OCIO should develop and implement monitoring and enforcement procedures to ensure that non-GFE devices (for example, BYOD), such as those owned by contractors or HUD employees, are either: (a) prohibited from connecting to the HUD network; or (b) properly authorized and configured before connection to the HUD network (IG FISMA metrics 2, 21, and 33).
- Status2023-OE-0001-19OpenClosed
HUD OCIO should develop and implement procedures and contract terms to enforce forfeiture of non-GFE devices (for example, BYOD), to allow for analysis when security incidents occur (IG FISMA metrics 33 and 55).
- Status2023-OE-0001-21OpenClosedClosed on August 26, 2024
HUD OCIO should develop and implement processes to monitor and analyze qualitative and quantitative performance measures for the effectiveness of its ISCM program (IG FISMA metric 47).
- Status2023-OE-0001-22OpenClosed
HUD OCIO should define a process and assign responsibility to evaluate the effectiveness of its incident response technologies and adjust configurations and toolsets to improve the incident response program (IG FISMA metric 58).
- Status2023-OE-0001-23OpenClosed
HUD OCIO should update its enterprisewide business impact prioritization analysis procedures to include system dependencies and the characterization of system components (IG FISMA metric 61).
2023-OE-0001a | December 20, 2023
Fiscal Year 2023 Federal Information Security Modernization Act of 2014 Penetration Test Evaluation Report
Chief Information Officer
- Status2023-OE-0001a-01OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-02OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-03OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-05OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-06OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2024-FW-0002 | December 15, 2023
CPD Could Improve the Timing of Delivery of Disaster Recovery Funding
Community Planning and Development
- Status2024-FW-0002-001-AOpenClosedClosed on October 23, 2024
We recommend that the Director of Disaster Recovery collect and record the number of days that it or other entities take to complete each milestone in the grant process.
- Status2024-FW-0002-001-BOpenClosedClosed on October 23, 2024
We recommend that the Director of Disaster Recovery establish timing benchmarks for the milestones at each significant step in the allocation and award process based on actual data accumulated for the various grants.
- Status2024-FW-0002-001-COpenClosedClosed on October 23, 2024
We recommend that the Director of Disaster Recovery take steps to ensure that the milestone point of allocation is formally defined and documented, to allow for accurate tracking of compliance with requirements.
2024-FW-1001 | October 27, 2023
The Puerto Rico Department of Housing Should Enhance Its Fraud Risk Management Practices
Community Planning and Development
- Status2024-FW-1001-001-AOpenClosedClosed on July 09, 2025
We recommend that the Deputy Assistant Secretary instruct PRDOH to implement a process to regularly conduct fraud risk assessments and determine a fraud risk profile. The fraud risk profile should include key findings and conclusions from the risk assessment, including the analysis of the types of fraud risks, their perceived likelihood and impact, risk tolerance, and the prioritization of risks.
- Status2024-FW-1001-001-BOpenClosedClosed on September 11, 2024
We recommend that the Deputy Assistant Secretary instruct PRDOH to improve fraud awareness initiatives, such as participating in organized antifraud conferences, reviewing the OIG’s Special Fraud Alerts, Bulletins, and Other Guidance, and attending fraud risk training tailored to the program’s fraud risk profile (including subrecipients).
- Status2024-FW-1001-001-COpenClosed
We recommend that the Deputy Assistant Secretary for Grant Programs evaluate PRDOH’s risk exposure and tolerance as part of HUD’s program-specific fraud risk assessment for disaster grant programs.
- Status2024-FW-1001-001-DOpenClosed
We recommend that the Deputy Assistant Secretary for Grant Programs coordinate with HUD’s Chief Risk Officer to (1) provide training and technical assistance to PRDOH with a focus on the design, implementation, and performance of fraud risk assessments, and (2) establish a fraud risk management framework for the organization.
- Status2024-FW-1001-001-EOpenClosed
We recommend that the Deputy Assistant Secretary for Grant Programs assess whether grantees have mature fraud risk management programs within the disaster recovery and mitigation programs.