HUD OCIO should identify needs to address Federal requirements by performing a gap analysis on its zero trust architecture strategic plan.
2023-OE-0007 | December 12, 2024
U.S. Department of Housing and Urban Development Personally Identifiable Information Risk Management in a Zero Trust Environment (2023-OE-0007) Evaluation Report
Chief Information Officer
- Status2023-OE-0007-01OpenClosedClosed on June 03, 2025
- Status2023-OE-0007-02OpenClosedClosed on June 03, 2025
HUD OCIO should establish a zero trust architecture implementation plan that includes milestones and resources to address all zero trust pillars.
2024-OE-0002a | December 11, 2024
Fiscal Year 2024 Federal Information Security Modernization Act of 2014 Penetration Test
Chief Information Officer
- Status2024-OE-0002a-10OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
Closed on April 30, 2025The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2024-OE-0002 | October 29, 2024
HUD FY 2024 Federal Information Security Modernization Act (FISMA) Evaluation Report
Chief Information Officer
- Status2024-OE-0002-05OpenClosedClosed on May 13, 2025
HUD OCIO should review its security training program and determine whether it should provide general cybersecurity awareness training to external users of its systems and data (IG FISMA metric 44).
2023-OE-0001 | January 29, 2024
HUD FY 2023 Federal Information Security Modernization Act (FISMA) Evaluation Report
Chief Information Officer
- Status2023-OE-0001-01OpenClosedClosed on July 30, 2025
HUD OCIO should implement a process to consistently update and maintain its inventory of hardware assets and ensure that the inventory is consistent with the automated discovery scans used to perform vulnerability, configurations, and continuous diagnostics and mitigation scans and use this inventory to consistently remove unauthorized hardware assets from the HUD network (IG FISMA metrics 2, 20, and 21).
- Status2023-OE-0001-02OpenClosedClosed on August 26, 2024
HUD OCIO should report at least 80 percent of its government-furnished equipment through the DHS CDM program (IG FISMA metric 2).
- Status2023-OE-0001-04OpenClosedClosed on September 02, 2025
HUD OCIO should update its software inventory policies and procedures to account for critical software as defined by EO 14028 (IG FISMA metrics 3 and 21).
- Status2023-OE-0001-05OpenClosedClosed on September 30, 2025
HUD OCIO should implement policies and procedures to maintain inventories of critical software and software licenses, critical software platforms, and all software installed on critical software platforms (both critical software and noncritical software) and use the inventory of critical software platforms and all software installed on them to ensure that only supported versions of software are used on those critical software platforms (IG FISMA metrics 3 and 21).
- Status2023-OE-0001-10OpenClosedClosed on September 30, 2025
HUD OCIO should ensure that external systems, such as cloud systems and cloud service providers, have and maintain configuration management plans that are consistent with HUD’s defined configuration management requirements (IG FISMA metric 19).
- Status2023-OE-0001-16OpenClosedClosed on August 26, 2024
HUD OCIO should implement procedures to ensure that digital identity risk assessments have been performed and documented in accordance with HUD’s defined procedures and Federal guidelines (IG FISMA metrics 30 and 31).
- Status2023-OE-0001-21OpenClosedClosed on August 26, 2024
HUD OCIO should develop and implement processes to monitor and analyze qualitative and quantitative performance measures for the effectiveness of its ISCM program (IG FISMA metric 47).
2023-FO-0008 | January 24, 2023
Assessment of HUD’s IT Infrastructure To Support Extensive Telework
Chief Information Officer
- Status2023-FO-0008-001-AOpenClosedClosed on May 24, 2023
Research, evaluate, and implement technical or alternative solutions to deploy essential computer software updates using appropriate secure methods to ensure that computer security updates occur in a timely manner to minimize risk to HUD’s systems and operations
- Status2023-FO-0008-002-AOpenClosedClosed on May 24, 2023
Research, evaluate, and implement technical solutions to provide additional improvements to VPN and related remote working capabilities of HUD system users.
- Status2023-FO-0008-002-BOpenClosedClosed on May 24, 2023
Perform routine VPN stress tests as part of its contingency planning and testing processes to regularly identify and remediate network performance issues and ensure that network capabilities are sufficient for teleworking.
- Status2023-FO-0008-003-AOpenClosedClosed on October 02, 2024
Research, evaluate, and implement technical solutions to resolve the user account management issues and the underlying issue in the technical environment.
2022-OE-0001 | September 30, 2022
HUD FY 2022 Federal Information Security Modernization Act (FISMA) Evaluation Report
Chief Information Officer
- Status2022-OE-0001-03OpenClosedClosed on September 16, 2025
HUD OCIO and the Office of Administration should implement procedures to ensure proper validation of media sanitization in accordance with HUD Media Protection Procedures 2.0 (February 2022) and form HUD 1067A, Certification of Sanitization (derived from metric 36).
- Status2022-OE-0001-05OpenClosedClosed on August 05, 2024
HUD OCIO should ensure that system owners and information system security officers consistently test their ISCPs and upload the test results to CSAM in accordance with HUD’s defined ISCP testing policy (derived from metric 63).
2021-OE-0001 | February 17, 2022
Fiscal Year 2021 Federal Information Security Modernization Act (FISMA) Evaluation Report
Chief Information Officer
- Status2021-OE-0001-03OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
Closed on September 03, 2025The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2021-OE-0001-05OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
Closed on April 30, 2025The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2021-OE-0001-06OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
Closed on October 10, 2023The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.