U.S. flag

An official website of the United States government Here’s how you know

The .gov means it’s official.

Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you're on a federal government site.

The site is secure.

The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Export
Date Issued

Chief Information Officer

  •  
    Status
      Open
      Closed
    2021-DP-0001-002-D
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2021-DP-0001-002-E
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2021-DP-0001-002-F
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2021-DP-0001-003-A
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2021-DP-0001-003-B
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2021-DP-0001-004-A
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

Housing

  •  
    Status
      Open
      Closed
    2021-FO-0003-001-I

    Implement the requirements of HUD’s current Debt Collection Handbook, to include (1) assigning a program office manager, (2) developing and implementing debt collection standard operating procedures, (3) designating program action officials, and (4) ensuring that program action officials are trained and perform debt collection duties in a timely manner in accordance with the Debt Collection Handbook; HUD Handbook 2000.06, REV-4, Audits Management System; and other pertinent guidance and policies to ensure the accurate reporting of receivables in the general ledger.

  •  
    Status
      Open
      Closed
    2021-FO-0003-001-J

    Review all executed repayment agreements in HUD’s Tenant Rental Assistance Certification System (TRACS) to determine which repayment agreements have not been fully repaid and represent an amount owed to HUD and work with OCFO to record these receivables.

  •  
    Status
      Open
      Closed
    2021-FO-0003-001-K

    Include a field in TRACS to identify which repayment agreements represent an amount owed to HUD and implement controls to ensure the accuracy of the listing in TRACS.

  •  
    Status
      Open
      Closed
    2021-FO-0003-001-L

    Develop and implement controls to track and enforce repayments owed to HUD to ensure that owners are not delinquent on their repayment agreements.

Housing

  •  
    Status
      Open
      Closed
    2021-LA-0802-001-A

    Adequately notify homeowners that, due to COVID-19, all FHA refund applications and supporting documents should be sent electronically to avoid delay in processing. This process should include (1) developing and expediting implementation of correspondence sent to homeowners with the application, (2) a notice of operational changes on HUD’s FHA refunds websites, (3) ensuring that HUD’s Does HUD Owe You a Refund website is updated to the most recent FHA Homeowners Fact Sheet, (4) an updated voice message from the call center including an accurate email, and (5) developing an updated script for call center agents for the initial contact with the homeowner, follow up, and contact with homeowners who already submitted their application by mail.

  •  
    Status
      Open
      Closed
    2021-LA-0802-001-B

    Conduct a privacy impact assessment for accepting homeowner FHA refund applications and supporting documentation that contain PII electronically to identify potential risks and develop and implement plans to mitigate those risks.

  •  
    Status
      Open
      Closed
    2021-LA-0802-001-C

    Develop and implement written policies and procedures for SFIOD to quickly respond to emergency situations when staff cannot return to the office. Procedures should include steps to quickly notify homeowners of any changes made to the FHA refund process.

Chief Information Officer

  •  
    Status
      Open
      Closed
    2020-OE-0001-01
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    Priority
    Priority

    We believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.

    Implement a software asset management capability for software and operating systems to ensure that software executes only from the authorized software inventory and all unauthorized software is blocked from executing on HUD's network.


    Status

    In April 2024, the Office of the Chief Information Officer reported that it was in the process of implementing a software management tool that would allow it to control which software is authorized to access the network. This is the first step to creating rules for allowing only authorized software to be used through HUD's endpoint security software. The final implementation of this new tool is expected by Quarter 2 of FY 2025.


    Analysis

    To fully address this recommendation, HUD must provide evidence that it has an automated whitelist and it is implemented as per the NIST Special Publication 800-167 or accept the risk and document mitigating measures via a Risk-Based Decision memorandum.

    Implementation of this recommendation will result in HUD having the capability to ensure only authorized software is used on HUD’s network based on its software asset listing.

  •  
    Status
      Open
      Closed
    2020-OE-0001-02
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2020-OE-0001-03
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2020-OE-0001-04
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2020-OE-0001-05
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2020-OE-0001-06
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.

  •  
    Status
      Open
      Closed
    2020-OE-0001-07
    Sensitive
    Sensitive

    Sensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.

    The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.