The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2024-OE-0002a | December 11, 2024
Fiscal Year 2024 Federal Information Security Modernization Act of 2014 Penetration Test
Chief Information Officer
- Status2024-OE-0002a-09OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
- Status2024-OE-0002a-11OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2024-OE-0002a-12OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2024-OE-0002a-13OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2025-FO-0003 | November 15, 2024
Audit of the U.S Department of Housing and Urban Development’s Fiscal Years 2024 and 2023 Financial Statements
Community Planning and Development
- Status2025-FO-0003-001-BOpenClosed
We recommend that the Deputy Assistant Secretary for Operations of Community Planning and Development enhance CPDs existing Grant Accrual Standard Operating Procedures to strengthen governance within CPD and to effectively work within the framework established by the OCFO in recommendation 1A. The updated procedures should include increased ownership and oversight over the reviews, authorizations, approvals, and changes to the CPD grant accrual estimates and methodology.
2023-OE-0007a | October 31, 2024
FHA Catalyst Personally Identifiable Information Risk Management in a Zero Trust Environment (2023-OE-0007a) Interim Evaluation Report
Housing
- Status2023-OE-0007a-02OpenClosed
Housing should refine access controls within the FHA Catalyst modules that are dynamic, are tailored to user actions, and require continuous reauthentication to ensure that users have access only to information needed.
- Status2023-OE-0007a-03OpenClosed
Housing should coordinate with HUD’s SOC to a. Ensure that FHA Catalyst user behavior monitoring logs are regularly captured and adequately reviewed for discrepancies in user activities. b. Establish program office responsibility for the log review process.
2024-OE-0002 | October 29, 2024
HUD FY 2024 Federal Information Security Modernization Act (FISMA) Evaluation Report
Chief Information Officer
- Status2024-OE-0002-01OpenClosed
HUD OCIO should a) resolve the conflicts between its Inventory of Automated Systems (IAS) policy and web applications policy to clarify if web applications will be inventories in IAS, the web application Sharepoint site, or both; and b) implement the chosen resolution to this conflict to develop a consistent inventory of web applications (IG FISMA metric 1).
- Status2024-OE-0002-02OpenClosed
HUD OCIO should implement an automated governance, risk, and compliance tool to manage risk from all sources across the three tiers of the organization in a timely manner. This recommendation updates FY 2021 FISMA recommendation number 5 (IG FISMA metrics 5, 9, and 10).
- Status2024-OE-0002-03OpenClosed
HUD OCIO should employ automation to maintain a timely and accurate view of security configuration information for all systems connected to its network (IG FISMA metric 20).
- Status2024-OE-0002-04OpenClosed
HUD OCIO should demonstrate that it can implement its defined security responses if a baseline configuration is changed without authorization. This can be shown by either a response to a real incident if one happens or through a testing exercise if there are no applicable incidents (IG FISMA metric 23).
2024-BO-0005 | September 24, 2024
FHEO Faces Challenges in Completing Investigations Within 100 Days
Fair Housing and Equal Opportunity
- Status2024-BO-0005-001-AOpenClosed
We recommend that HUD’s Deputy Assistant Secretary for Fair Housing and Equal Opportunity update protocols to promote consistent expectations for timely supervisory, legal, and headquarters reviews of complex cases.
- Status2024-BO-0005-001-BOpenClosed
We recommend that HUD’s Deputy Assistant Secretary for Fair Housing and Equal Opportunity review and update the MOUs with OGC for each region to identify and remove inefficiencies that can lead to longer FHEO investigation times and OGC review times and identify best practices that can be implemented across all regions.
- Status2024-BO-0005-001-COpenClosed
We recommend that HUD’s Deputy Assistant Secretary for Fair Housing and Equal Opportunity review and update investigative processes followed by each regional office to identify best practices that can be implemented across all regions and identify and remove inefficiencies that can lead to longer investigation times.
2024-LA-0001 | September 17, 2024
HUD Grantees Need to Enhance Monitoring of ESG CARES Act Subrecipients
Community Planning and Development
- Status2024-LA-0001-001-AOpenClosed
Take corrective action for the subrecipient monitoring and agreement issues cited for eight of the ESG-CV grantees reviewed, and provide additional guidance and technical assistance as needed to ensure that they understand requirements.
- Status2024-LA-0001-001-BOpenClosed
Develop and implement additional subrecipient monitoring training and guidance for all ESG grantees.
2024-CH-1003 | August 20, 2024
The Housing Authority of the City of Los Angeles Did Not Adequately Manage Lead-Based Paint in Its Public Housing Units
Public and Indian Housing
- Status2024-CH-1003-001-COpenClosed
Obtain lead-based paint risk assessments for the five developments for which hazard reduction work was completed and perform the required reevaluations.
- Status2024-CH-1003-001-DOpenClosed
Determine whether the remaining five developments (Imperial Courts, Mar Vista Gardens, Nickerson Gardens, Ramona Gardens, and Rancho San Pedro) have deteriorated paint and if so, obtain lead-based paint risk assessments and reevaluations when applicable.
2024-NY-0002 | August 09, 2024
HUD Addressed Multifamily Mortgage Application Processing Delays, but Additional Action Is Needed To Manage Future Backlogs
Housing
- Status2024-NY-0002-001-AOpenClosed
Require that the PLUS system for receiving, processing, and assigning applications tracks applications and captures application intake, screening, and status, including key dates; captures data on the type of underwriter used; includes a portal for receiving documents and communicating with lenders; and generates FHA loan numbers. This will allow HUD to identify, monitor, and address processing delays and issues on a continuous basis; evaluate its performance and processes; and manage future challenges.
- Status2024-NY-0002-001-BOpenClosed
Update policies and procedures to include methods that will be used when applications exceed underwriter capacity, align intake and screening processes, and explain when timeframes will be enforced, including in PLUS.