The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2021-OE-0001 | Febrero 17, 2022
Fiscal Year 2021 Federal Information Security Modernization Act (FISMA) Evaluation Report
Chief Information Officer
- Status2021-OE-0001-04OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
- Status2021-OE-0001-08OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
PrioridadPriorityWe believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
Define and communicate policies and procedures to ensure that its products, system components, systems, and services comply with its cybersecurity and SCRM requirements. This recommendation includes:
- Identification and prioritization of externally provided systems (new and legacy), components, and services.
- How HUD maintains awareness of its upstream suppliers.
- The integration of acquisition processes tools, and techniques to use the acquisition process to protect the supply chain.
- Contract tools or procurement methods to confirm that contractors are meeting their obligations (derived from OIG FISMA metric 14).
Status
The Office of the Chief Information Officer (OCIO) estimated it would complete corrective action for this recommendation by August 2023. In May 2024, HUD OIG reviewed the OCIO progress in closing this recommendation as part of the FY 2024 FISMA evaluation. At that time, OCIO provided its draft SCRM Policy, draft SCRM Procedures, final SCRMES Charter, and a SCRM Technical Roadmap. Additionally, HUD provided agency-specific clauses. As of January 2025, HUD has not issued finalized SCRM policies and procedures.
Analysis
To fully address this recommendation, HUD must establish that it has defined and communicated policies and procedures to ensure that its products, system components, systems, and services comply with its cybersecurity and SCRM requirements.
Implementation of this recommendation will result in HUD continuing to mature in supply chain risk management, establishing and defining the policies and procedures of SCRM requirements as they relate to systems and system components.
- Status2021-OE-0001-09OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2021-OE-0001-10OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2021-OE-0001-11OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2021-OE-0001-13OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2021-OE-0001-14OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2021-OE-0001-15OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2021-OE-0001-16OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2021-OE-0001-20OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2021-OE-0001-21OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
- Status2021-OE-0001-22OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2022-BO-0001 | Febrero 07, 2022
HUD Did Not Have Adequate Policies and Procedures for Ensuring That Public Housing Agencies Properly Processed Requests for Reasonable Accommodation
Public and Indian Housing
- Status2022-BO-0001-001-COpenClosed
We recommend that HUD’s Deputy Assistant Secretary for Public Housing and Voucher Programs conduct additional outreach efforts to educate tenants and PHAs on their rights and responsibilities related to requests for reasonable accommodation, including technical assistance, webinars, and external communications to inform PHAs about their responsibilities and how to evaluate requests for reasonable accommodation, and help families understand their rights.
2022-LA-1001 | Enero 20, 2022
The Los Angeles Homeless Services Authority, Los Angeles, CA, Did Not Always Administer Its Continuum of Care Program in Accordance With HUD Requirements
Community Planning and Development
- Status2022-LA-1001-002-AOpenClosed$824,302Questioned Costs
Recommendations with questioned costs identify costs: (A] resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B] that are not supported by adequate documentation (also known as an unsupported cost]; or (C] that appear unnecessary or unreasonable.
Adequately support the eligibility of payroll costs or repay its CoC grants $824,302 from non-Federal funds.
- Status2022-LA-1001-002-BOpenClosed$55,545Questioned Costs
Recommendations with questioned costs identify costs: (A] resulting from an alleged violation of a law, regulation, contract, grant, or other document or agreement governing the use of Federal funds; (B] that are not supported by adequate documentation (also known as an unsupported cost]; or (C] that appear unnecessary or unreasonable.
Adequately support the eligibility of rent costs or repay its CoC grants $55,545 from non-Federal funds.
- Status2022-LA-1001-002-COpenClosed
Develop and implement additional written procedures and controls to ensure that employees charge time in accordance with program requirements and that the Authority fully documents and supports that salary and rental cost allocations are charged to its CoC grants in accordance with its cost allocation plan.
2022-NY-1001 | Enero 11, 2022
The Buffalo Municipal Housing Authority, Buffalo, NY, Needs To Improve Its Management of the Commodore Perry Homes Development To Address Longstanding Concerns
Public and Indian Housing
- Status2022-NY-1001-001-FOpenClosed
Develop and implement a plan to use available asset repositioning options for the remaining 284 public housing units at the Commodore Perry Homes development, including 274 dwelling units and 10 nondwelling units.
- Status2022-NY-1001-001-GOpenClosed
Develop and implement a plan for the original property related to the 46 units converted under the RAD transfer of assistance option to ensure that the property and proceeds from its disposition are used in accordance with requirements.
2022-LA-0001 | Enero 07, 2022
HUD Did Not Have Adequate Controls in Place to Track, Monitor, and Issue FHA Refunds Owed to Homeowners
Housing
- Status2022-LA-0001-001-DOpenClosed
Develop and implement written policies and procedures regarding the designation of legal representation for applicants.
2022-AT-0001 | Enero 05, 2022
Opportunities Exist To Improve CPD’s Oversight of and Monitoring Tools for Slow-Spending Grantees
Community Planning and Development
- Status2022-AT-0001-001-COpenClosed
Establish a reasonable timeframe for grantees to resolve DRGR flags or at a minimum, if a flag cannot be resolved within the established timeframe, have the grantee provide a remediating comment explaining why the flag could not be resolved and a proposed timeline for resolution.