HUD OCIO should develop and implement processes to monitor and analyze qualitative and quantitative performance measures for the effectiveness of its ISCM program (IG FISMA metric 47).
2023-OE-0001 | January 29, 2024
HUD FY 2023 Federal Information Security Modernization Act (FISMA) Evaluation Report
Chief Information Officer
- Status2023-OE-0001-21OpenClosed
- Status2023-OE-0001-22OpenClosed
HUD OCIO should define a process and assign responsibility to evaluate the effectiveness of its incident response technologies and adjust configurations and toolsets to improve the incident response program (IG FISMA metric 58).
- Status2023-OE-0001-23OpenClosed
HUD OCIO should update its enterprisewide business impact prioritization analysis procedures to include system dependencies and the characterization of system components (IG FISMA metric 61).
2023-OE-0001a | December 20, 2023
Fiscal Year 2023 Federal Information Security Modernization Act of 2014 Penetration Test Evaluation Report
Chief Information Officer
- Status2023-OE-0001a-01OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-02OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-03OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-05OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-06OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2023-KC-0003 | March 28, 2023
Opportunities Exist for Ginnie Mae To Improve Its Guidance and Process for Troubled Issuers
Government National Mortgage Association
- Status2023-KC-0003-001-AOpenClosedPriorityPriority
We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Update its policy and procedures to define its authority for marketing troubled issuer portfolios and the conditions that must exist to extinguish issuers using rapid relocation.
Corrective Action Taken
As of February 2024, HUD addressed this recommendation in a Management Decision by providing the updated extinguishment SOP, the Rapid Relocation Process Flow, and the Rapid Relocation Extinguishment Process Steps, updated to include the conditions that must be present to execute an extinguishment using rapid relocation. We believe that these guidance enhancements will help Ginnie Mae to reduce exposure to risk when facilitating a sale and transfer of a troubled issuer’s portfolio and ensure that it sells portfolios with limited loss to the Government and with minimal disruption to the mortgage market.
- Status2023-KC-0003-001-BOpenClosedPriorityPriority
We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Update its policy and procedures to define what type of information Ginnie Mae may disclose and how it will handle protected information before extinguishment.
Corrective Action Taken
Ginnie Mae provided the updated SOP to clarify data and information handling through all phases of the termination/extinguishment process. Specifically, the updated procedures state that Ginnie Mae does not disclose Issuer or portfolio information within the Rapid Relo process. Ginnie Mae provided clarity in this enhancement that will reduce exposure to risk when facilitating a sale and transfer of a troubled issuer’s portfolio and ensure that it sells portfolios with limited loss to the Government and with minimal disruption to the mortgage market.
- Status2023-KC-0003-001-COpenClosedPriorityPriority
We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Update its Policies and procedures to define how Ginnie Mae will determine the portfolio value and price before Sale.
Corrective Action Taken
Ginnie Mae updated its Rapid Relocation Extinguishment SOP to specify the valuation model for rapid relocations will use the same valuation models as other extinguishment options, including examples of portfolio valuation. We believe this guidance enhancement will help Ginnie Mae to reduce exposure to risk when facilitating a sale and transfer of a troubled issuer’s portfolio and ensure that it sells portfolios with limited loss to the Government and with minimal disruption to the mortgage market.
- Status2023-KC-0003-001-DOpenClosedPriorityPriority
We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Update its policies and procedures to define how Ginnie Mae intends to identify and evaluate prospective buyers to ensure its ability to absorb the extinguished portfolio before executing the purchase and sale agreement.
Corrective Action Taken
Ginnie Mae updated its Rapid Relocation Extinguishment SOP to require an Impact Analysis Evaluation of each prospective buyer under the Rapid Relocation Extinguishment program. The Impact Analysis Evaluation mirrors similar activities performed on select standard Pool Transfer participants and includes details (such as adjusted net worth, delinquency, loan court and total unpaid principle balance) to confirm prospective buyers are able to absorb the extinguished portfolio before executing the purchase and sale agreement. We believe this guidance enhancement will help Ginnie Mae to reduce exposure to risk when facilitating a sale and transfer of a troubled issuer’s portfolio and ensure that it sells portfolios with limited loss to the Government and with minimal disruption to the mortgage market.
- Status2023-KC-0003-002-AOpenClosed
Assesses what information Ginnie Mae needs from the MSS to ensure that they have the capacity for a large- or multiple-issuer extinguishment.
- Status2023-KC-0003-002-BOpenClosed
Prescribes how the contracting officer representative will review information provided by the MSS and provide actionable feedback to ensure MSS readiness.
2023-KC-0004 | March 28, 2023
Ginnie Mae Mostly Implemented a Crisis Readiness Program That Followed Federal Guidance
Government National Mortgage Association
- Status2023-KC-0004-002-AOpenClosed
Develop and implement an agencywide crisis readiness plan addressing likely hazards arising from a crisis. This guidance should include all key elements that meet CIGFO crisis guidance.
2021-OE-0007 | February 17, 2023
HUD’s Robotic Process Automation Program Was Not Efficient or Effective
Chief Information Officer
- Status2021-OE-0007-01OpenClosed
Identify short- and long-term plans for the RPA program that align its capabilities, staffing needs, funding projections, and mission needs.
- Status2021-OE-0007-02OpenClosed
Implement procedures to capture and monitor centralized logs to maintain appropriate visibility into bot activities and provide for auditability of bot actions.
- Status2021-OE-0007-03OpenClosed
Implement procedures to periodically review RPA system access and remove access for users that are not authorized or no longer have a need to use the system.
- Status2021-OE-0007-04OpenClosed
Implement procedures to ensure that attended bots use the security rights and credentials of the attending user.
2023-FO-0008 | January 24, 2023
Assessment of HUD’s IT Infrastructure To Support Extensive Telework
Chief Information Officer
- Status2023-FO-0008-001-AOpenClosed
Research, evaluate, and implement technical or alternative solutions to deploy essential computer software updates using appropriate secure methods to ensure that computer security updates occur in a timely manner to minimize risk to HUD’s systems and operations