FY 2024 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation Report
HUD OCIO should review its security training program and determine whether it should provide general cybersecurity awareness training to external users of its systems and data (IG FISMA metric 44).
FHA Catalyst PII Risk Management in a Zero Trust Environment Interim Report
Housing should include zero trust requirements as part of the Housing Strategic Roadmap for Housing Modernization.
FHA Catalyst PII Risk Management in a Zero Trust Environment Interim Report
Housing should refine access controls within the FHA Catalyst modules that are dynamic, are tailored to user actions, and require continuous reauthentication to ensure that users have access only to information needed.
FHA Catalyst PII Risk Management in a Zero Trust Environment Interim Report
Housing should coordinate with HUD’s SOC to
a. Ensure that FHA Catalyst user behavior monitoring logs are regularly captured and adequately reviewed for discrepancies in user activities.
b. Establish program office responsibility for the log review process.
Timing of PHAs' Lead-Based Paint Visual Assessments
Issue guidance to PHAs clarifying the timing of unit inspections and lead-based paint visual assessments to address the misinterpretation caused by the terms “annual” and “every 12 months.”
Transmittal of Independent Public Accountant's Audit Report on the U.S. Department of Housing and Urban Development's Fiscal Years 2024 and 2023 Financial Statements
We recommend that the Chief Financial Officer enhance existing policies to establish a formal grant accrual risk management framework to help ensure consistent standards across HUD with regard to the development, review, and execution of the grant accrual and validation. This framework should include 1) identifying grant accrual estimation risk, assessing the magnitude of this risk, and managing the risks that arise when using certain…
Transmittal of Independent Public Accountant's Audit Report on the U.S. Department of Housing and Urban Development's Fiscal Years 2024 and 2023 Financial Statements
We recommend that the Deputy Assistant Secretary for Operations of Community Planning and Development enhance CPDs existing Grant Accrual Standard Operating Procedures to strengthen governance within CPD and to effectively work within the framework established by the OCFO in recommendation 1A. The updated procedures should include increased ownership and oversight over the reviews, authorizations, approvals, and changes to the CPD grant…
The Data in CAIVRS Did Not Agree With the Data in FHA's Default and Claims Systems
Update selection rules for CAIVRS to provide for complete reporting of all ineligible borrowers to put $9.5 million to better use.
Status
In 2020, HUD suspended reporting delinquencies and defaults to the Credit Alert Verification Reporting System (CAIVRS) because these debts are owed to the lender and are not delinquent federal debt. A debt is not delinquent until payment is overdue to HUD for a deficiency judgment against the…
FHA's Office Of Asset Sales Did Not Have Adequate Information To Measure Its Loan Sales' Program Success
Update the Conveyance, Assignment, and Assumption Agreement to require purchasers to report final property outcomes and identifying information including those of third-party purchasers when applicable.
FHA's Office Of Asset Sales Did Not Have Adequate Information To Measure Its Loan Sales' Program Success
Enhance data collection and processing controls to ensure consistency in reporting data.
FHA's Office Of Asset Sales Did Not Have Adequate Information To Measure Its Loan Sales' Program Success
Enhance existing demonstration guidance within the Conveyance, Assignment, and Assumption Agreement to provide further detail regarding documentation retention requirements.
FY24 FISMA Penetration Test Report
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
FY24 FISMA Penetration Test Report
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
FY24 FISMA Penetration Test Report
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
FY24 FISMA Penetration Test Report
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
FY24 FISMA Penetration Test Report
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
FY24 FISMA Penetration Test Report
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
FY24 FISMA Penetration Test Report
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
FY24 FISMA Penetration Test Report
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
The Stark Metropolitan Housing Authority, Canton, OH, Did Not Always Comply With Federal and Its Own Procurement Requirements
For the contract activities during the period of January 1, 2020, through April 2022, the Director should require the Authority to support the contract modifications and the reasonableness of the increased costs for four contracts (0824, 0505, 1023 and 0731) or repay its Public Housing Operating Fund or Capital Fund program from non-Federal funds for any amount determined not to be reasonable.