The Offices of Audit and Evaluation supervise and conduct independent and objective audits, evaluations, and other reviews of U.S. Department of Housing and Urban Development (HUD] programs and activities to ensure they operate economically, efficiently, and effectively. This page contains links to our audit and evaluation reports and memoranda.
Public and Indian Housing (PIH) Information Technology (IT) Modernization Resourcing Evaluation
The OIG Office of Evaluation is initiating an evaluation of the U.S. Department of Housing and Urban Development’s (HUD) Public and Indian Housing (PIH) Information Technology (IT) Modernization program. The objectives are to assess the IT Modernization process for Enterprise Voucher Management System (EVMS) and Housing Information Portal (HIP) systems that support key PIH programs.
Marzo 31, 2025
Work Start Notification
#2025-OE-0007
Operational Effectiveness of IT Security Controls
To assess the operational effectiveness of security controls for selected HUD IT systems or functions.
Marzo 31, 2025
Work Start Notification
#2025-OE-0006
U.S. Department of Housing and Urban Development Personally Identifiable Information Risk Management in a Zero Trust Environment (2023-OE-0007) Evaluation Report
The OIG evaluated the U.S. Department of Housing and Urban Development’s (HUD) progress in applying zero trust security principles to protect personally identifiable information (PII). HUD maintained a significant number of records that contain PII with limited zero trust controls in place to secure these data. In FY 2022, HUD established a zero trust implementation plan to help the agency address the five zero trust...
Diciembre 12, 2024
Report
#2023-OE-0007
Fiscal Year (FY) 2025 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation
HUD OIG is conducting the Fiscal Year (FY) 2025 evaluation of the HUD's information security (InfoSec) program and practices, as required by the Federal Information Security Modernization Act of 2014 (FISMA). The objectives are to (1) perform an independent evaluation of the effectiveness of HUD’s InfoSec program and practices as required by FISMA; (2) test the effectiveness of HUD’s InfoSec policies, procedures, and practices through...
Noviembre 01, 2024
Work Start Notification
#2025-OE-0001
HUD FY 2024 Federal Information Security Modernization Act (FISMA) Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to...
Octubre 29, 2024
Report
#2024-OE-0002
HUD Personal Identifiable Information Risk Management in a Zero Trust Environment
HUD OIG is performing this evaluation to assess HUD’s capability to meet privacy and data protection requirements and provide appropriate stakeholders with an understanding of any related potential risks to HUD’s data and the operational mission. The evaluation will also provide HUD an independent assessment of the level of maturity it has reached in developing the data and identify pillars of CISA's zero-trust architecture. The...
Enero 01, 2024
Work Start Notification
#2023-OE-0007
Fiscal Year (FY) 2024 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation
HUD OIG is conducting the Fiscal Year (FY) 2024 evaluation of the HUD's information security program and practices, as required by the Federal Information Security Modernization Act of 2014 (FISMA). The objectives are to (1) assess the maturity level of HUD’s InfoSec program and practices based on the annual IG FISMA reporting metrics. The assessment will include 20 core IG metrics that are evaluated annually and group 2 of the...
Diciembre 01, 2023
Work Start Notification
#2024-OE-0002
Fiscal Year 2023 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation
HUD OIG is conducting the Fiscal Year (FY) 2023 evaluation of the HUD's information security program and practices, as required by the Federal Information Security Modernization Act of 2014 (FISMA). The objectives are to (1) assess the maturity level of HUD’s IS programs and practices based on the annual IG FISMA reporting metrics. The assessment will include 20 core IG metrics that are evaluated annually and group 1 of the...
Diciembre 01, 2022
Work Start Notification
#2023-OE-0001
HUD FY 2022 Federal Information Security Modernization Act (FISMA) Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation...
Septiembre 30, 2022
Report
#2022-OE-0001
Geospatial Data Act of 2018, Fiscal Year 2022
We audited the U.S. Department of Housing and Urban Development’s (HUD) efforts to meet the Geospatial Data Act of 2018 (the Act).Our audit objective was to determine whether HUD met the 13 responsibilities stated in the Act with regard to its collection, production, acquisition, maintenance, distribution, use, and preservation of geospatial data. The Act also generally requires covered agencies provide access to geospatial data...
Septiembre 30, 2022
Report
#2022-LA-0004
Fiscal Year 2022 Federal Information Security Modernization Act (FISMA) of 2014 Evaluation
HUD OIG is conducting the Fiscal Year (FY) 2022 evaluation of the HUD's information security program and practices, as required by the Federal Information Security Modernization Act (FISMA) of 2014. The objectives are to (1) assess the maturity level of HUD's information security policies and procedures, (2) prepare responses for the core Inspector General (IG) FISMA reporting metrics, and (3) test and verify the technical...
Enero 01, 2022
Work Start Notification
#
IT Modernization Roadmap
We will review HUD OCIO’s most recent IT modernization roadmap and strategy along with any other supporting documentation HUD can provide regarding modernization progress and milestones. Specifically, we will identify the various ongoing modernization projects within the roadmap and obtain documentation about the status of the individual projects. We will interview HUD officials knowledgeable about HUD’s modernization plans to confirm...
Diciembre 01, 2020
Work Start Notification
#2021-OE-0003
HUD IT Challenges and Recommendation Topic Brief
To provide the HUD Secretary, senior leadership and Congress with an overview of the current status of Information Technology (IT) at HUD, the challenges they have overcome since the first 2018 IT Brief and the challenges they continue to face.
Diciembre 01, 2020
Work Start Notification
#2021-OE-0004
HUD FY 2021 Federal Information Security Modernization Act of 2014 (FISMA) Assessment
In accordance with the mandated work in FISMA, we are conducting the annual evaluation of information security practices, policies, and procedures established by HUD and the HUD Office of the Chief Information Officer. As part of the evaluation, we will also review 8 sample systems within 7 HUD program offices. Two products will result from our work; the mandated DHS CyberScope FISMA IG metrics report and a narrative report.
Diciembre 01, 2020
Work Start Notification
#2021-OE-0001
HUD FY 2020 Federal Information Security Modernization Act of 2014 (FISMA) Assessment
In accordance with the mandated work in FISMA, we are conducting the annual evaluation of information security practices, policies, and procedures established by HUD and the HUD Office of the Chief Information Officer. As part of the evaluation, we will also review 8 sample systems within 7 HUD program offices. Two products will result from our work; the mandated DHS CyberScope FISMA IG metrics report and a narrative report.
Diciembre 01, 2019
Work Start Notification
#2020-OE-0001