U.S. flag

An official website of the United States government Here’s how you know

The .gov means it’s official.

Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you're on a federal government site.

The site is secure.

The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Export
Date Issued

Chief Information Officer

  •  
    Status
      Open
      Closed
    2023-OE-0001-17

    HUD OCIO should define a plan to meet the logging requirements at all event logging maturity levels (basic, intermediate, advanced) in accordance with OMB M-21-31. This plan should include logging sufficient to allow for reviewing privileged user activities (IG FISMA metrics 32 and 54).

  •  
    Status
      Open
      Closed
    2023-OE-0001-18

    HUD OCIO should develop and implement monitoring and enforcement procedures to ensure that non-GFE devices (for example, BYOD), such as those owned by contractors or HUD employees, are either: (a) prohibited from connecting to the HUD network; or (b) properly authorized and configured before connection to the HUD network (IG FISMA metrics 2, 21, and 33).

  •  
    Status
      Open
      Closed
    2023-OE-0001-19

    HUD OCIO should develop and implement procedures and contract terms to enforce forfeiture of non-GFE devices (for example, BYOD), to allow for analysis when security incidents occur (IG FISMA metrics 33 and 55).

  •  
    Status
      Open
      Closed
    2023-OE-0001-21

    HUD OCIO should develop and implement processes to monitor and analyze qualitative and quantitative performance measures for the effectiveness of its ISCM program (IG FISMA metric 47).

  •  
    Status
      Open
      Closed
    2023-OE-0001-22

    HUD OCIO should define a process and assign responsibility to evaluate the effectiveness of its incident response technologies and adjust configurations and toolsets to improve the incident response program (IG FISMA metric 58).

  •  
    Status
      Open
      Closed
    2023-OE-0001-23

    HUD OCIO should update its enterprisewide business impact prioritization analysis procedures to include system dependencies and the characterization of system components (IG FISMA metric 61).

Chief Information Officer

  •  
    Status
      Open
      Closed
    2023-OE-0001a-01
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2023-OE-0001a-02
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2023-OE-0001a-03
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2023-OE-0001a-05
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2023-OE-0001a-06
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

Chief Procurement Officer

  •  
    Status
      Open
      Closed
    2023-BO-0002-001-A

    We recommend that the Chief Procurement Officer direct the contracting officers to review the current FSM contracts’ QASP and update accordingly to ensure that all minimum contract requirements are included.

  •  
    Status
      Open
      Closed
    2023-BO-0002-001-B

    We recommend that the Chief Procurement Officer direct the contracting officers to oversee the implementation of the current FSM contracts’ QASP.

  •  
    Status
      Open
      Closed
    2023-BO-0002-001-C

    We recommend that the Chief Procurement Officer require the contracting officers to implement the policies and procedures in the HUD Acquisition Policy and Procedure Handbook for completion of HUD’s FSM contractor performance assessment reports in CPARS to ensure that Government past performance is documented properly and in a timely manner, at least annually, for use by all Federal agencies and maintained in the contract files.

  •  
    Status
      Open
      Closed
    2023-BO-0002-001-D

    We recommend that the Chief Procurement Officer require all staff involved in the oversight of FSM contracts to maintain the required documentation in the official contract file identified by HUD policy to support the contracts.

  •  
    Status
      Open
      Closed
    2023-BO-0002-001-F

    We recommend that the Chief Procurement Officer require the contracting officers to formally designate CORs in a timely manner and maintain the required documentation in the proper location identified in the relevant HUD policies and procedures, which fully supports the CORs’ oversight of the FSM contract.

Chief Information Officer

  •  
    Status
      Open
      Closed
    2021-OE-0007-01

    Identify short- and long-term plans for the RPA program that align its capabilities, staffing needs, funding projections, and mission needs.

  •  
    Status
      Open
      Closed
    2021-OE-0007-02

    Implement procedures to capture and monitor centralized logs to maintain appropriate visibility into bot activities and provide for auditability of bot actions.

  •  
    Status
      Open
      Closed
    2021-OE-0007-03

    Implement procedures to periodically review RPA system access and remove access for users that are not authorized or no longer have a need to use the system.

  •  
    Status
      Open
      Closed
    2021-OE-0007-04

    Implement procedures to ensure that attended bots use the security rights and credentials of the attending user.