The U.S. Department of Housing and Urban Development’s (HUD) Office of Inspector General audited the Office of the Chief Human Capital Officer based on concerns about security risks of hard drives in multifunction devices. Our objective was to determine whether HUD had documented and implemented procedures to effectively remove sensitive data from the hard drives of multifunction devices before disposing of them.
HUD did not monitor or test the overwrite process for multifunction devices to ensure that the process effectively sanitized data from multifunction device hard drives. It also did not have a detailed plan in place to ensure proper sanitization of the devices’ hard drives before disposal.
We recommend that the Chief Human Capital Officer develop and implement a plan to monitor and test HUD’s overwrite process for hard drives on its multifunction devices to ensure that the process is effective. We also recommend that the Chief Human Capital Officer develop and implement a plan to ensure that all sensitive data are effectively sanitized from the hard drives of its multifunction devices before the they are disposed of.