HUD’s Office of Administration, in coordination with OCIO, should update and communicate its PII minimization plan. The plan should include detailed procedures to regularly review and remove unnecessary PII collections in accordance with OMB Circular A-130 (IG FISMA metric 35).
2023-OE-0001 | January 29, 2024
HUD FY 2023 Federal Information Security Modernization Act (FISMA) Evaluation Report
Office of Administration
- Status2023-OE-0001-20OpenClosedClosed on October 04, 2024
Chief Information Officer
- Status2023-OE-0001-01OpenClosedClosed on July 30, 2025
HUD OCIO should implement a process to consistently update and maintain its inventory of hardware assets and ensure that the inventory is consistent with the automated discovery scans used to perform vulnerability, configurations, and continuous diagnostics and mitigation scans and use this inventory to consistently remove unauthorized hardware assets from the HUD network (IG FISMA metrics 2, 20, and 21).
- Status2023-OE-0001-02OpenClosedClosed on August 26, 2024
HUD OCIO should report at least 80 percent of its government-furnished equipment through the DHS CDM program (IG FISMA metric 2).
- Status2023-OE-0001-04OpenClosedClosed on September 02, 2025
HUD OCIO should update its software inventory policies and procedures to account for critical software as defined by EO 14028 (IG FISMA metrics 3 and 21).
- Status2023-OE-0001-05OpenClosedClosed on September 30, 2025
HUD OCIO should implement policies and procedures to maintain inventories of critical software and software licenses, critical software platforms, and all software installed on critical software platforms (both critical software and noncritical software) and use the inventory of critical software platforms and all software installed on them to ensure that only supported versions of software are used on those critical software platforms (IG FISMA metrics 3 and 21).
- Status2023-OE-0001-10OpenClosedClosed on September 30, 2025
HUD OCIO should ensure that external systems, such as cloud systems and cloud service providers, have and maintain configuration management plans that are consistent with HUD’s defined configuration management requirements (IG FISMA metric 19).
- Status2023-OE-0001-16OpenClosedClosed on August 26, 2024
HUD OCIO should implement procedures to ensure that digital identity risk assessments have been performed and documented in accordance with HUD’s defined procedures and Federal guidelines (IG FISMA metrics 30 and 31).
- Status2023-OE-0001-21OpenClosedClosed on August 26, 2024
HUD OCIO should develop and implement processes to monitor and analyze qualitative and quantitative performance measures for the effectiveness of its ISCM program (IG FISMA metric 47).
2022-OE-0008 | January 19, 2024
U.S. Department of Housing and Urban Development Employee Retention
Office of Chief Human Capital Officer
- Status2022-OE-0008-01OpenClosedClosed on January 19, 2024
Implement a transparent process for reviewing open-ended exit survey results and sharing those results with ODEEO, as appropriate, and program offices while still protecting former employees’ confidentiality.
- Status2022-OE-0008-02OpenClosedClosed on January 19, 2024
Assess what departing employees mean when they indicate that organizational culture is a motivation for leaving HUD.
- Status2022-OE-0008-03OpenClosedClosed on August 15, 2024
Develop guidance for the program offices to identify the causes behind high attrition rates in governmentwide high-risk MCOs and field offices in large cities.
- Status2022-OE-0008-04OpenClosedClosed on November 20, 2024
Develop guidance for program offices to develop program office-specific action plans to address any causes found for high attrition rates in governmentwide high-risk MCOs and field offices in large cities.
- Status2022-OE-0008-05OpenClosedClosed on January 17, 2025
Create a single, unified agency-specific MCO list updated to reflect current progress toward closing skills gaps.
2021-OE-0010 | March 10, 2023
The Office of Community Planning and Development’s Use of Remote Monitoring
Community Planning and Development
- Status2021-OE-0010-01OpenClosedClosed on September 14, 2023
Complete and update the system security plans for GMP and DRGR and issue an SSN justification memorandum.
- Status2021-OE-0010-02OpenClosedClosed on March 10, 2023
Identify and provide additional role-based training, guidance, and instructions to CPD employees on how to appropriately handle and safeguard PII encountered during monitoring.
- Status2021-OE-0010-03OpenClosedClosed on May 02, 2023
Reinforce the use and admissibility of photographs and videos for evidence collection while remote monitoring.
- Status2021-OE-0010-04OpenClosedClosed on March 10, 2023
Identify strategic opportunities to use remote monitoring early in the FY to maximize its responsibility to oversee and monitor its grantees and then use remote monitoring when those opportunities arise.
2021-OE-0011b | February 28, 2023
Improvements are Needed to the U.S. Department of Housing and Urban Development's Processes for Monitoring Elevated Blood Lead Levels and Lead-Based Paint Hazards in Public Housing
Public and Indian Housing
- Status2021-OE-0011b-02OpenClosedClosed on November 13, 2023
Create a plan and timeline that outlines OFO’s proposal to make necessary improvements to the EBLL tracker, such as moving it to a different platform.
- Status2021-OE-0011b-03OpenClosedClosed on August 25, 2023
Provide field office staff access to historical data in the EBLL tracker to be readily available as needed, with adequate protection of PII.
- Status2021-OE-0011b-04OpenClosedClosed on December 08, 2023
Update the EBLL tracker to show whether one or multiple children have an EBLL and whether the unit, building, or development previously had an EBLL reported.