HUD OCIO should define a process and assign responsibility to evaluate the effectiveness of its incident response technologies and adjust configurations and toolsets to improve the incident response program (IG FISMA metric 58).
2023-OE-0001 | January 29, 2024
HUD FY 2023 Federal Information Security Modernization Act (FISMA) Evaluation Report
Chief Information Officer
- Status2023-OE-0001-22OpenClosed
- Status2023-OE-0001-23OpenClosed
HUD OCIO should update its enterprisewide business impact prioritization analysis procedures to include system dependencies and the characterization of system components (IG FISMA metric 61).
2023-OE-0001a | December 20, 2023
Fiscal Year 2023 Federal Information Security Modernization Act of 2014 Penetration Test Evaluation Report
Chief Information Officer
- Status2023-OE-0001a-01OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-02OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-03OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-05OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2023-OE-0001a-06OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2023-IG-002 | May 31, 2023
Management Alert: HUD Should Take Additional Steps to Protect Contractor Employees Who Disclose Wrongdoing
Other
- Status2023-IG-002-1OpenClosedPriorityPriority
We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
HUD (a) identify all contracts related to its programs that pre-date July 1, 2013 and that have not yet been modified to include Section 4712 whistleblower protections; and (b) review all contracts entered into on or after July 1, 2013, to ensure they include a clause that requires contractors to comply with Section 4712.
Status
HUD provided a Management Plan that identifies actions HUD is taking to address the recommendation. The OIG and HUD have not reached an agreement that the actions proposed will fully address the recommendations. Additionally, HUD has not completed several of the proposed actions and is still collecting information that responds to the recommendations.
Analysis
To fully address this recommendation, HUD must (a) identify all contracts related to its programs that pre-date July 1, 2013, and that have not yet been modified to include Section 4712 whistleblower protections; and (b) review all contracts entered on or after July 1, 2013, to ensure they include a clause that requires contractors to comply with Section 4712.
Implementation of this recommendation will ensure that Section 4712 whistleblower protections will apply to all individuals working for HUD contractors.
- Status2023-IG-002-2OpenClosedPriorityPriority
We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Seek voluntary cooperation from program participants to proactively modify pre-2013 contracts for the purpose of including a clause requiring compliance with Section 4712.
Status
HUD provided a Management Plan that identifies actions HUD is taking to address the recommendation. The OIG and HUD have not reached an agreement that the actions proposed will fully address the recommendations. Additionally, HUD has not completed several of the proposed actions and is still collecting information that responds to the recommendations.
Analysis
To fully address this recommendation, HUD must provide evidence that it has sought voluntary cooperation from program participants to proactively modify pre-2013 contracts for the purpose of including a clause requiring compliance with Section 4712.
Implementation of this recommendation will ensure that Section 4712 whistleblower protections will apply to all individuals working for HUD contractors.
- Status2023-IG-002-3OpenClosedPriorityPriority
We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Use its best efforts to include a clause requiring compliance with Section 4712 at the time of major modifications to contracts with program participants with whom HUD is unable to gain voluntary cooperation.
Status
HUD provided a Management Plan that identifies actions HUD is taking to address the recommendation. The OIG and HUD have not reached an agreement that the actions proposed will fully address the recommendations. Additionally, HUD has not completed several of the proposed actions and is still collecting information that responds to the recommendations.
Analysis
To fully address this recommendation, HUD must provide evidence that it has taken steps to ensure that it includes a clause requiring compliance with Section 4712 at the time of major modifications to contracts with program participants with whom HUD is unable to gain voluntary cooperation.
Implementation of this recommendation will ensure that Section 4712 whistleblower protections will apply to all individuals working for HUD contractors.
- Status2023-IG-002-4OpenClosed
HUD seek legislative authority to expeditiously include Section 4712 protections within contracts for which HUD believes it must otherwise wait until there is a major modification.
- Status2023-IG-002-5OpenClosed
HUD develop and implement controls to ensure that the provisions of Section 4712 are included in all contracts.
2021-OE-0007 | February 17, 2023
HUD’s Robotic Process Automation Program Was Not Efficient or Effective
Chief Information Officer
- Status2021-OE-0007-01OpenClosed
Identify short- and long-term plans for the RPA program that align its capabilities, staffing needs, funding projections, and mission needs.
- Status2021-OE-0007-02OpenClosed
Implement procedures to capture and monitor centralized logs to maintain appropriate visibility into bot activities and provide for auditability of bot actions.
- Status2021-OE-0007-03OpenClosed
Implement procedures to periodically review RPA system access and remove access for users that are not authorized or no longer have a need to use the system.
- Status2021-OE-0007-04OpenClosed
Implement procedures to ensure that attended bots use the security rights and credentials of the attending user.
2023-FO-0008 | January 24, 2023
Assessment of HUD’s IT Infrastructure To Support Extensive Telework
Chief Information Officer
- Status2023-FO-0008-001-AOpenClosed
Research, evaluate, and implement technical or alternative solutions to deploy essential computer software updates using appropriate secure methods to ensure that computer security updates occur in a timely manner to minimize risk to HUD’s systems and operations
- Status2023-FO-0008-002-AOpenClosed
Research, evaluate, and implement technical solutions to provide additional improvements to VPN and related remote working capabilities of HUD system users.
- Status2023-FO-0008-002-BOpenClosed
Perform routine VPN stress tests as part of its contingency planning and testing processes to regularly identify and remediate network performance issues and ensure that network capabilities are sufficient for teleworking.
- Status2023-FO-0008-003-AOpenClosed
Research, evaluate, and implement technical solutions to resolve the user account management issues and the underlying issue in the technical environment.