HUD’s Office of Administration, in coordination with OCIO, should update and communicate its PII minimization plan. The plan should include detailed procedures to regularly review and remove unnecessary PII collections in accordance with OMB Circular A-130 (IG FISMA metric 35).
2023-OE-0001 | January 29, 2024
HUD FY 2023 Federal Information Security Modernization Act (FISMA) Evaluation Report
Office of Administration
- Status2023-OE-0001-20OpenClosed
2020-OE-0001 | November 30, 2020
HUD Fiscal Year 2020 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation Report
Office of Administration
- Status2020-OE-0001-17OpenClosedSensitiveSensitive
Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2019-OE-0002a | June 25, 2020
HUD Personally Identifiable Information (PII) Records Protection and Management
Office of Administration
- Status2019-OE-0002a-01OpenClosed
Designate a Senior Agency Official for Records Management at the Assistant Secretary level or its equivalent.
- Status2019-OE-0002a-02OpenClosed
Update and issue agency formal records policy, including detailed procedures and requirements for completing and maintaining program office and agencywide inventories of systems, records, and PII.
- Status2019-OE-0002a-06OpenClosed
Establish and disseminate a policy on safeguarding or prohibiting the transportation of PII records out of the office for telework purposes.
- Status2019-OE-0002a-08OpenClosed
Standardize processes and duties for all RMLOs.
- Status2019-OE-0002a-09OpenClosed
Conduct a staffing resource assessment for the HUD records program and identify any skills gaps or resource needs.
2018-OE-0001 | September 13, 2018
HUD Privacy Program Evaluation Report
Office of Administration
- Status2018-OE-0001-01OpenClosed
Ensure the privacy program is staffed with experienced personnel (such as a Chief Privacy Officer) to manage the operational aspects of the program.
- Status2018-OE-0001-02OpenClosed
Issue a notice at the Secretary level delegating and clarifying the authority and responsibilities of the SAOP and Privacy Office
- Status2018-OE-0001-03OpenClosed
A. Document the roles and specific responsibilities of all positions assigned privacy responsibilities. B. Communicate these responsibilities on a recurring basis, at least annually, to individuals holding these positions.
- Status2018-OE-0001-04OpenClosed
Implement thorough human capital processes to ensure execution of the HUD privacy program and all its requirements
- Status2018-OE-0001-05OpenClosed
Finalize and approve the draft privacy program strategic plan
- Status2018-OE-0001-06OpenClosed
Ensure the privacy program is integrated with the enterprise risk program and that privacy risks are incorporated into the agency risk management process
- Status2018-OE-0001-07OpenClosed
Establish an executive leadership dashboard to communicate continuous monitoring of key program risks and issues
- Status2018-OE-0001-08OpenClosed
A. Develop an internal privacy program communication plan to describe how privacy issues will be disseminated and best practices will be shared. B. Implement the communication plan
- Status2018-OE-0001-09OpenClosed
Develop a dedicated budget to address Privacy Office training needs and initiatives
- Status2018-OE-0001-10OpenClosed
Update all privacy guidance to reflect current Federal requirements and processes.
- Status2018-OE-0001-11OpenClosed
Implement a formal process for the Privacy Office to issue and communicate privacy guidance, requirements, and deadlines.
- Status2018-OE-0001-12OpenClosed
Update and continue to maintain a central collaboration area to include all current privacy program policies, procedures, and guidance
- Status2018-OE-0001-13OpenClosed
Establish standard processes to ensure consistent work flow and communications between program office and Privacy Office personnel