The U.S. Department of Housing and Urban Development (HUD) Office of Inspector General (OIG) conducted an evaluation of the operational effectiveness of information technology (IT) security controls for the HUDUSER system, which is operated by HUD’s Office of Policy Development and Research (PD&R). The OIG identified four significant weaknesses involving website security, underscoring the need to strengthen technical security controls. To address these findings, we provide eight new recommendations, which will be formally tracked by our office. These recommendations are designed to enhance HUD’s IT security posture by preventing web-based threats from exploiting the HUDUSER system, ensuring the integrity and confidentiality of sensitive information. The OIG has determined that this report contains sensitive information and is therefore not appropriate for public disclosure.