U.S. flag

An official website of the United States government Here’s how you know

The .gov means it’s official.

Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you're on a federal government site.

The site is secure.

The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Export
Date Issued

Government National Mortgage Association

  •  
    Status
      Open
      Closed
    2023-KC-0003-001-C
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Update its Policies and procedures to define how Ginnie Mae will determine the portfolio value and price before Sale.


    Corrective Action Taken

    Ginnie Mae updated its Rapid Relocation Extinguishment SOP to specify the valuation model for rapid relocations will use the same valuation models as other extinguishment options, including examples of portfolio valuation. We believe this guidance enhancement will help Ginnie Mae to reduce exposure to risk when facilitating a sale and transfer of a troubled issuer’s portfolio and ensure that it sells portfolios with limited loss to the Government and with minimal disruption to the mortgage market.

  •  
    Status
      Open
      Closed
    2023-KC-0003-001-D
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Update its policies and procedures to define how Ginnie Mae intends to identify and evaluate prospective buyers to ensure its ability to absorb the extinguished portfolio before executing the purchase and sale agreement.


    Corrective Action Taken

    Ginnie Mae updated its Rapid Relocation Extinguishment SOP to require an Impact Analysis Evaluation of each prospective buyer under the Rapid Relocation Extinguishment program. The Impact Analysis Evaluation mirrors similar activities performed on select standard Pool Transfer participants and includes details (such as adjusted net worth, delinquency, loan court and total unpaid principle balance) to confirm prospective buyers are able to absorb the extinguished portfolio before executing the purchase and sale agreement. We believe this guidance enhancement will help Ginnie Mae to reduce exposure to risk when facilitating a sale and transfer of a troubled issuer’s portfolio and ensure that it sells portfolios with limited loss to the Government and with minimal disruption to the mortgage market.

Public and Indian Housing

  •  
    Status
      Open
      Closed
    2021-OE-0011b-06
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    PIH in coordination with other HUD offices as necessary, research and address potential causes of the variance in the number of EBLL cases among States on the EBLL tracker and identify solutions that are within HUD's control.


    Status

    As of November 13, 2024, the PIH Office of Field Operations (OFO) had completed its outreach data collection and identified 9 public housing authorities that had not completed the required EBLL reporting actions and that OFO informed the field office directors overseeing the appropriate PHAs that they had until November 6, 2024, to upload the proper information to the trackers. As of January 29, 2025, OFO field office directors and their staff were still updating and inputting EBLL cases and relevant documentation into the EBLL tracker due to delays in responses from PHAs. The estimated completion date is February 28, 2025.


    Analysis

    To fully address this recommendation, OFO must provide evidence that it coordinated with other HUD offices and identified the causes of the variances in the number of EBLL cases among states on the EBLL tracker. OFO must also demonstrate that it fully remedied the causes of the variances. Alternatively, OFO must provide an explanation sufficient to support a claim that it could not identify the causes of the variances or develop and implement solutions for problems it identified in its research.

    Implementation of this recommendation will result in improved HUD data of EBLL cases of children living in public housing across the country. Accurate reporting of EBLL cases to HUD is essential so that HUD can ensure PHAs take effective environmental interventions that help prevent additional lead exposure.

Lead Hazard Control

  •  
    Status
      Open
      Closed
    2021-OE-0011b-01
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Define and communicate policies and procedures to ensure that its products, system components, systems, and services comply with its cybersecurity and SCRM requirements. This recommendation includes:

    • Identification and prioritization of externally provided systems (new and legacy), components, and services.
    • How HUD maintains awareness of its upstream suppliers.
    • The integration of acquisition processes tools, and techniques to use the acquisition process to protect the supply chain.
    • Contract tools or procurement methods to confirm that contractors are meeting their obligations (derived from OIG FISMA metric 14).

    Status

    On January 17, 2025, the Office of Lead Hazard Control and Healthy Homes (OLHCHH) informed HUD OIG that the Office of the Federal Register published a notice, Modifying HUD’s Elevated Blood Lead Level Threshold for Children Under Age 6 Who Are Living in Certain HUD-Assisted Target Housing Covered by the Lead Safe Housing Rule. The notice announced that HUD is lowering its EBLL threshold from 5 to 3.5 µg/dL for a child under the age of 6, consistent with the CDC’s current blood lead reference value of 3.5 µg/dL, effective January 17, 2025. Next, OLHCHH will assist the Office of Community Planning and Development, the Office of Multifamily Housing Programs, and the Office of Public and Indian Housing to draft, circulate, and publish EBLL notices. The estimated completion date is June 30, 2025.


    Analysis

    To fully address this recommendation, OLHCHH must provide evidence that it has updated its regulations, policies, and procedures so that they are consistent with CDC’s lowered blood lead reference value of 3.5 ug/dL.

    Implementation of this recommendation will help ensure children living in public housing with elevated blood lead levels receive effective environmental interventions.

Chief Financial Officer

  •  
    Status
      Open
      Closed
    2023-FO-0001-001-A
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Perform a complete agency-wide fraud risk assessment (which incorporates the fraud risk assessments performed at the program level) and use the results to develop and implement an agency-wide plan to move HUD’s fraud risk management program out of the ad hoc phase.


    Status

    HUD has made steady progress in building its Fraud Risk Management program. In FY 2024, HUD received Congressional approval to establish the Office of the Chief Risk Officer (OCRO). With its Fraud Risk Management Policy in place since 2022, OCRO worked with the HUD Risk Management Council to develop the Department’s approach and establish a cross-functional approach for Fraud Risk Management program accountability. The CRO also completed a fraud risk exposure assessment method that enables the Department to provide a risk-based approach to prioritize program fraud risk assessments and a department-level Fraud Risk Management Playbook to align HUD’s cross-functional activities and accountability to the GAO Fraud Risk Framework and CFO Council practices. The CRO is also working on tools and templates that are being customized for HUD program offices to help them complete their fraud risk assessments. Priority program offices are targeted to complete fraud risk assessments in 2025.


    Analysis

    While HUD has made progress in the area of fraud risk management, there is still work to be done for HUD to complete an entity-wide fraud risk assessment. HUD's exposure analysis will help it to determine where to focus its efforts. The Department still needs to conduct program-specific fraud risk assessments. Based on the demonstration by Multifamily Housing (MFH), we believe that MFH has made great progress in its fraud risk assessment, and we are encouraged that it has identified areas of weakness that it plans to target. However, Public and Indian Housing (PIH) and Community Planning and Development (CPD) have not been able to demonstrate progress in this area. We believe that the tools and templates the OCRO is developing, along with the continued support, will help PIH and CPD to complete these assessments.

    To fully address this recommendation, HUD must provide evidence that it has performed an agency-wide fraud risk assessment performed at the program level, adopted and implemented its fraud risk assessment program departmental policy, and that each HUD program office has established office-specific risk programs.

Public and Indian Housing

  •  
    Status
      Open
      Closed
    2023-CH-0001-001-B
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Requires the REAC in coordination with OFO to determine the number of developments and associated units that contain lead-based paint and lead-based paint hazards.


    Status

    In May 2023, HUD published a final rule establishing a new approach to defining and assessing housing quality: The National Standards for the Physical Inspection of Real Estate. Public Housing regulations were amended, and Public Housing program participants were required to comply with this final rule and use the NSPIRE standards starting July 1, 2023. The Real Estate Assessment Center and Office of Field Operations will collaborate with the Office of Lead Hazard Control and Healthy Homes, the Office of Policy Development and Research, and a statistician to evaluate data collected under the NSPIRE inspection program to estimate the number of public housing developments and associated units that contain lead-based paint and lead-based paint hazards. As of November 2024, PIH reported that inspections have had a slow start due to procurement delays. Additionally, the NSPIRE system did not get the requested functionality to collect lead inspections. The final action target date is March 31, 2025.


    Analysis

    To address this recommendation, HUD will need to provide evidence that it collected and evaluated data under NSPIRE and estimated the number of public housing developments and associated units that contain lead-based paint and lead-based paint hazards.

    Implementation of this recommendation will assist HUD in working with PHAs to address the public housing units that contain lead-based paint and lead-based paint hazards and help HUD’s oversight of units in need of hazard reduction.

Lead Hazard Control

  •  
    Status
      Open
      Closed
    2023-IG-0001-001-A
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Update applicable requirements to require assisted property owners, including PHAs, to maintain adequate documentation to support their determinations that maintenance and hazard reduction activities that disturb surfaces with lead-based paint qualify for the de minimis exemption from the lead-safe work practices under the Lead Safe Housing Rule.


    Status

    To address this recommendation, OLHCHH agreed to:

    • Issue a notice to assisted target housing owners and public housing agencies on the de minimis exception citing the correct application of the de minimis threshold; describing appropriate documentation methods for the application of the de minimis threshold; and recommendations of best practices for documenting applications.
    • Collect additional data regarding the use of the de minimis threshold, including information on how private and public housing owners: (a) determine how much paint in target housing will be disturbed during a maintenance or rehabilitation project; (b) use the paint disturbance area information; (c) monitor the amount of paint disturbed in projects that are designed to disturb de minimis amounts of paint in target housing.
    • Design and conduct webinars, including at least one for each program office’s major categories of stakeholders on requirements and best practices pertaining to the de minimis exception under the Lead Safe Housing Rule and its implementation; record the webinars on the HUD website (e.g., on HUD Exchange) for future viewing by stakeholders; and conduct outreach promoting the webinars

    The Office of Lead Hazard Control and Healthy Homes had drafted guidance on the de minimis exception to the Lead Safe Housing Rule for PIH, Multifamily Housing, and CPD and submitted it through the clearance process on September 26, 2024, with an October 9, 2024, due date. Through October 17, six concurring comments were received as was one non-concurring comment. The OLHCHH continues to revise the draft guidance in consideration of the comments. In May 2023, HUD published a final rule establishing a new approach to defining and assessing housing quality: The National Standards for the Physical Inspection of Real Estate. Public Housing regulations were amended, and Public Housing program participants were required to comply with this final rule and use the NSPIRE standards starting July 1, 2023. The Real Estate Assessment Center and Office of Field Operations will collaborate with the Office of Lead Hazard Control and Healthy Homes, the Office of Policy Development and Research, and a statistician to evaluate data collected under the NSPIRE inspection program to estimate the number of public housing developments and associated units that contain lead-based paint and lead-based paint hazards. As of November 2024, PIH reported that inspections have had a slow start due to procurement delays. Additionally, the NSPIRE system did not get the requested functionality to collect lead inspections. The final action target date is March 31, 2025.


    Analysis

    To implement this recommendation, HUD needs to provide evidence that it has implemented the three actions OLHCHH agreed to complete.

    Implementation of this recommendation and associated corrective actions will ensure assisted property owners are sufficiently informed regarding the requirements to support their determinations that maintenance and hazard reduction activities that disturb surfaces with lead-based paint qualify for the de minimis exemption from the lead-safe work practices under the Lead Safe Housing Rule and that assisted property owners are conducting this work safely, thereby ensuring households are residing in safe and healthy HUD-assisted housing.

Housing

  •  
    Status
      Open
      Closed
    2022-KC-0002-001-B
    $1,506,887,996
    Funds Put to Better Use

    Recommendations that funds be put to better use estimate funds that could be used more efficiently. For example, recommendations that funds be put to better use could result in reductions in spending, deobligation of funds, or avoidance of unnecessary spending.

    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Develop a control to detect loans that did not maintain the required flood insurance to put $1.5 billion to better use by avoiding potential future costs to the FHA insurance fund from inadequately insured properties.


    Corrective Action Taken

    In November 2022, FHA published the Acceptance of Private Flood Insurance for FHA-Insured Mortgages final rule (Docket No. FR-6084-F-02) in the Federal Register and issued Mortgagee Letter 2022-18, Acceptance of Private Flood Insurance for FHA-Insured Mortgages (ML 2022-18). These policy changes not only strengthened Single Family’s Mortgagee requirements regarding flood insurance, but they also introduced the ability for borrowers and Mortgagees to purchase private flood insurance. In January 2023, the sections in ML 2022-18 that pertain to HUD’s forward mortgage programs were superseded by the FHA Single Family Housing Policy Handbook (Handbook 4000.1), adding a requirement that the Mortgagee review all FHA-insured properties annually to determine if the property is located within a Special Flood Hazard Area (SFHA). For properties located within a SFHA, the Mortgagee must ensure flood insurance is in force for the life of the mortgage and that the property has sufficient flood insurance coverage. To ensure compliance with the policy requirements, the Mortgagee must include updated flood insurance information for properties where flood insurance is required in the Servicing and Claims File. In addition, Handbook 4000.1 includes flood insurance servicing policy updates. HUD submitted a revised management decision reflecting this action on June 22, 2023.

Chief Information Officer

  •  
    Status
      Open
      Closed
    2021-OE-0001-08
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Define and communicate policies and procedures to ensure that its products, system components, systems, and services comply with its cybersecurity and SCRM requirements. This recommendation includes:

    • Identification and prioritization of externally provided systems (new and legacy), components, and services.
    • How HUD maintains awareness of its upstream suppliers.
    • The integration of acquisition processes tools, and techniques to use the acquisition process to protect the supply chain.
    • Contract tools or procurement methods to confirm that contractors are meeting their obligations (derived from OIG FISMA metric 14).

    Status

    The Office of the Chief Information Officer (OCIO) estimated it would complete corrective action for this recommendation by August 2023. In May 2024, HUD OIG reviewed the OCIO progress in closing this recommendation as part of the FY 2024 FISMA evaluation. At that time, OCIO provided its draft SCRM Policy, draft SCRM Procedures, final SCRMES Charter, and a SCRM Technical Roadmap. Additionally, HUD provided agency-specific clauses. As of January 2025, HUD has not issued finalized SCRM policies and procedures.


    Analysis

    To fully address this recommendation, HUD must establish that it has defined and communicated policies and procedures to ensure that its products, system components, systems, and services comply with its cybersecurity and SCRM requirements.

    Implementation of this recommendation will result in HUD continuing to mature in supply chain risk management, establishing and defining the policies and procedures of SCRM requirements as they relate to systems and system components.

Community Planning and Development

  •  
    Status
      Open
      Closed
    2022-AT-0001-001-B
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Update its policies and procedures for tracking expenditures related to slow-spending grantees, including steps for assisting the grantees to expedite spending (including the grantee’s steps or actions to address slow spending), identifying the reasons for the delays with the grant, and documenting the outcome of its efforts.


    Corrective Action Taken

    CPD updated guidance addressing grantee slow spending through technical assistance, including actions grant managers can take when grantee expenditures do not appear to be “on pace” to meet the expenditure deadlines, and demonstrated it is providing technical assistance to grantees during monitoring. CPD also issued an additional Standard Monitoring Findings and Corrective Actions Guide for its staff to promote a consistent framework for crafting monitoring findings and the corrective actions needed to resolve identified deficiencies and prevent future occurrences. This new resource provides general guidance and examples for presenting Finding components in monitoring reports for fourteen topics including, “Failure to Meet Timeliness of Expenditures Requirements.

2020-OE-0004 | November 17, 2021

HUD’s Processes for Managing IT Acquisitions

Chief Procurement Officer

  •  
    Status
      Open
      Closed
    2020-OE-0004-03
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Evaluate IT acquisition process workflows and identify ways to simplify the processes, facilitate more effective stakeholder coordination across offices, and create efficiencies when possible.


    Status

    The Office of the Chief Procurement Officer (OCPO) had agreed to an estimated completion date of March 2024. In November 2024, OCPO submitted additional evidence for closure; however, the evidence did not identify how the revisions to the process will address efficiency issues. The OIG requested further information that identifies improvements in the IT acquisition process.


    Analysis

    To fully address this recommendation, HUD must provide evidence that it has published its standard operating procedures resulting from its evaluation of workflows and efforts to simplify processes and facilitate more effective coordination.

    Implementation of this recommendation will result in defined IT acquisition process workflow procedures to increase efficiency and ensure coordination across program offices.

Public and Indian Housing

  •  
    Status
      Open
      Closed
    2021-CH-0001-001-B
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Establish and implement a plan for the unused and unfunded vouchers to mitigate or prevent additional vouchers from becoming unused and unfunded […]


    Corrective Action Taken

    HUD established and implemented a plan for the unused and unfunded vouchers, aiming to mitigate or prevent additional vouchers from becoming unused and unfunded. PIH's plan included the following, among other actions:

    • Determining the scope of HUD's statutory and regulatory authority to offset and reallocate vouchers.
    • Issuing Office of Public and Indian Housing Notice 2020-29, titled Guidance for Running an Optimized Housing Choice Voucher Program.
    • Continuing the work of HUD's landlord taskforce, engaging in listening sessions with major PHA industry groups, and conducting outreach to increase landlord participation in the HCV Program.
    • Developing research by HUD's Office of Policy Development and Research on the best methods for adjusting fair market rents and addressing specific challenges in local communities to increase utilization in the HCV Program.

Office of Chief Human Capital Officer

  •  
    Status
      Open
      Closed
    2020-OE-0002-06
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Create and implement a knowledge management strategy, such as developing standard operating procedures, reference sheets, and program office fact sheets.


    Corrective Action Taken

    OCHCO developed and implemented client profiles for each HUD program office to address knowledge loss and the need for offices to explain or reexplain their mission and functions. The profiles will serve as a central repository to learn about the various programs and missions of HUD and will allow OCHCO staff, other key HUD program office staff, and HUD’s service provider staff to view critical information for each HUD program office.

Housing

  •  
    Status
      Open
      Closed
    2021-KC-0004-001-A
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Develop a comprehensive process to ensure that complaints received by HUD’s Multifamily Housing Clearinghouse are resolved in a timely manner.


    Status

    In October 2023, the Office of Multifamily Housing reported that it had sought funding for system enhancements to coordinate tenant complaints. HUD is transitioning the Multifamily Clearinghouse responsibilities to the Federal Housing Administration (FHA) Resource Center. The FHA Resource Center has a system that will allow tracking and monitoring of customer calls. As of November 2024, the Office of Multifamily Housing requested the closure of this recommendation because it did not receive the requested funding for system enhancements, and its alternative action of using the FHA Resource Center to track and monitor customer calls did not work. As of January 2025, the Office of Multifamily plans to propose a revised management decision to HUD OIG with alternative actions to address the recommendation.


    Analysis

    To fully address this recommendation, HUD needs to develop a comprehensive process to ensure that complaints received by HUD are resolved in a timely manner.

    Implementation of this recommendation will result in a timelier resolution of complaints submitted by those living in multifamily member housing units.

  •  
    Status
      Open
      Closed
    2021-KC-0004-001-B
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Develop agencywide policies and procedures for the intake, monitoring, and tracking of health and safety complaints.


    Status

    In October 2023, HUD stated that it will develop policies and procedures for Multifamily properties for the intake, monitoring, and tracking of health and safety complaints it receives. The Office of Multifamily Housing has not yet updated its policies and procedures. With no comprehensive, automated, real-time system in place, there was no direction to give the field staff, Multifamily Clearinghouse, or the Performance Based Contract Administrators other than what they were already doing. HUD was in the process of developing an automated monitoring system in the FHA resource center to allow tracking of individual calls and the call’s subject, such as health and safety. HUD missed the final action target date of December 31, 2022, and a new completion goal was set for February 2025. As of November 2024, the Office of Multifamily Housing requested the closure of this recommendation because it did not receive the requested funding for system enhancements, and its alternative action of using the FHA Resource Center to track and monitor customer calls did not work. As of January 2025, the Office of Multifamily plans to submit a revised management decision to HUD OIG with alternative actions to address the recommendation.


    Analysis

    To fully address this recommendation, HUD must provide evidence that it has developed and implemented policies and procedures for the Multifamily properties for the intake, monitoring, and tracking of health and safety complaints it receives when using the FHA’s automated monitoring system.

    Implementation of this recommendation will result in HUD having a more efficient process for taking in, monitoring, and tracking health and safety complaints and aid HUD in more efficiently addressing those complaints.

Chief Information Officer

  •  
    Status
      Open
      Closed
    2021-OE-0003-01
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Develop an enterprise-wide IT modernization strategy that establishes a framework to align with the IT modernization roadmap.


    Corrective Action Taken

    In January, 2024, HUD provided an OCIO approved an IT Modernization strategy that established a framework that aligned with its IT modernization roadmap. The strategy addressed each of the recommendation components (a. roles and responsibilities, b. prioritization of modernization initiatives, c. coordination process between OCIO and program offices, d. phased approach, and e. how lessons learned will be captured.

Community Planning and Development

  •  
    Status
      Open
      Closed
    2020-OE-0003-01
    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Develop and issue a departmentwide policy that notes that radon is a radioactive substance and outlines HUD's requirements to test for and mitigate excessive radon levels in accordance with 24 CFR 50.3(i)(1) and 58.5(i)(2)(i).


    Corrective Action Taken

    None Given.

Chief Information Officer

  •  
    Status
      Open
      Closed
    2020-OE-0001-01
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Implement a software asset management capability for software and operating systems to ensure that software executes only from the authorized software inventory and all unauthorized software is blocked from executing on HUD's network.


    Status

    In April 2024, the Office of the Chief Information Officer reported that it was in the process of implementing a software management tool that would allow it to control which software is authorized to access the network. This is the first step to creating rules for allowing only authorized software to be used through HUD's endpoint security software. The final implementation of this new tool is expected by Quarter 2 of FY 2025.


    Analysis

    To fully address this recommendation, HUD must provide evidence that it has an automated whitelist and it is implemented as per the NIST Special Publication 800-167 or accept the risk and document mitigating measures via a Risk-Based Decision memorandum.

    Implementation of this recommendation will result in HUD having the capability to ensure only authorized software is used on HUD’s network based on its software asset listing.

  •  
    Status
      Open
      Closed
    2020-OE-0001-15
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Implement multifactor authentication mechanisms for all nonprivileged users who access information systems that process, store, or transmit PII.


    Status

    The Office of the Chief Information Officer reported that it has implemented a new software security solution to implement multifactor authentication, starting with a pilot on 15 FHA systems. In October 2024, HUD received additional funds through the Technology Modernization Fund for this project enterprisewide.


    Analysis

    To fully address the recommendation, HUD must implement multifactor authentication enterprisewide.

    Implementation of this recommendation will result in an enterprise-wide identity and access management solution. Users will be required to use multifactor authentication methods to access HUD data, networks, and devices.

  •  
    Status
      Open
      Closed
    2020-OE-0001-16
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Implement multifactor authentication mechanisms for all privileged users who access information systems that process, store, or transmit PII.


    Status

    The Office of the Chief Information Officer reported that it has implemented a new software security solution to implement multifactor authentication, starting with a pilot on 15 FHA systems. In October 2024, HUD received additional funds through the Technology Modernization Fund for this project enterprisewide.


    Analysis

    To fully address this recommendation, HUD must implement the eICAM plan it developed with the funding it received.

    Implementation of this recommendation will result in an enterprise-wide identity and access management solution. Users will be required to use multifactor authentication methods to access HUD data, networks, and devices.