FY 2024 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation Report
HUD OCIO should demonstrate that it can implement its defined security responses if a baseline configuration is changed without authorization. This can be shown by either a response to a real incident if one happens or through a testing exercise if there are no applicable incidents (IG FISMA metric 23).
FY 2024 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation Report
HUD OCIO should review its security training program and determine whether it should provide general cybersecurity awareness training to external users of its systems and data (IG FISMA metric 44).