HUD Fiscal Year 2017 Federal Information Security Modernization Act Of 2014 (FISMA) Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to assess…
October 30, 2017
Report
#2017-OE-0007
HUD Web Application Security Evaluation Report
Enforce the requirement for all HUD web applications and services to be approved and authorized by OCIO. The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
Corrective Action Taken
In January 2023, HUD's Office of the Chief Information Officer developed and released a Web Applications Directive to all HUD program…
July 05, 2017
Report
#2016-OE-0002
Federal Information Security Modernization Act (FISMA) Fiscal Year 2016 Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to assess…
November 09, 2016
Report
#2016-OE-0006
Federal Information Security Modernization Act (FISMA) Fiscal Year 2015 Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs the Office of Inspector General (OIG) to conduct an annual evaluation of the U.S. Department of Housing and Urban Development (HUD) information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and…
November 19, 2015
Report
#2015-OE-0001
Fiscal Year 2015 Review of Information System Controls in Support of the Financial Statements Audit
We reviewed information system controls over the U.S. Department of Housing and Urban Development’s (HUD) computing environment. This review was conducted as part of the Office of Inspector General’s audit of HUD’s financial statements for fiscal year 2015 under the Chief Financial Officer’s Act of 1990.
The OIG has determined that the contents of this report would not be appropriate for public disclosure and has therefore limited its…
November 11, 2015
Report
#2016-DP-0001
HUD Information Technology (IT) Modernization Report
Office of Evaluation, IT Evaluation Division (iTED) conducted an evaluation of HUD’s IT Modernization program, which included reviews on the implementation and maturity of HUD’s capital planning and investment control (CIPIC) process and Enterprise Architecture (EA) program. With the corroboration of HUD’s Office of Chief Information Officer (OCIO), the report focuses on three major IT programs and policies within the CPIC and EA programs: IT…
September 29, 2015
Report
#2015-OE-0002
Memorandum Report on HUD’s Processes used to Report Information Technology Investments on IT Dashboard
The Office of Evaluation performed preliminary research of the HUD Office of the Chief Information Officer’s (OCIO) management of the agency’s reporting of financial and project information on the Federal IT Dashboard (Dashboard). The objective of the evaluation was to determine if OCIO processes ensured accurate IT investment information was reported on the Dashboard. We found that project managers did not consistently follow…
April 28, 2015
Report
#2014-OE-0007
Fiscal Year 2014 Review of Information Systems Controls in Support of the Financial Statements Audit
We reviewed information system controls over the U.S. Department of Housing and Urban Development’s (HUD) computing environment. This review was conducted as part of the Office of Inspector General’s audit of HUD’s financial statements for fiscal year 2014 under the Chief Financial Officer’s Act of 1990.
The OIG has determined that the contents of this report would not be appropriate for public disclosure and has therefore limited its…
February 22, 2015
Report
#2015-DP-0005
Federal Information Security Management Act (FISMA) Fiscal Year 2014 Evaluation Report
The Federal Information Security Management Act of 2002 (FISMA) directs the Office of Inspector General (OIG) to conduct an annual evaluation of the U.S. Department of Housing and Urban Development (HUD) information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and…
November 13, 2014
Report
#2014-OE-0003
HUD Privacy Program Evaluation Report
Federal organizations have a fundamental responsibility to protect the privacy of individuals and their personally identifiable information (PII) that is collected, used, maintained, shared, and disposed of by agency programs and information systems. The management of U.S. Department of Housing and Urban Development (HUD) programs demands the availability and use of extensive amounts of financial, demographic, and personal information. HUD is…
April 29, 2014
Report
#2014-ITED-0001
Federal Information Security Management Act (FISMA) Fiscal Year 2013 Evaluation Report
The Federal Information Security Management Act of 2002 (FISMA) directs the Office of Inspector General (OIG) to conduct an annual evaluation of the U.S. Department of Housing and Urban Development (HUD) information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and…
November 28, 2013
Report
#2013-iTED-0001
HUD Staff SSN Breach
We have completed a review to determine whether HUD followed proper policies and procedures in responding to a breach of personally identifiable information which occurred on September 21, 2012. Specifically, for this incident, we identified what actions were taken and any deficiencies within HUD policies, plans, or current practices. We determined that HUD responded to the incident properly, following United States Computer Emergency…
November 04, 2012
Memorandum
#2013-DP-0801
Review of the National Environmental Policy Act and Core Activity Modules Within the Recovery Act Management and Performance System
We audited the U.S. Department of Housing and Urban Development’s (HUD) management procedures, practices, and controls related to the Recovery Act Management and Reporting System (RAMPS). Our objective was to assess its capability to record and provide data required by the American Recovery and Reinvestment Act of 2009 on which HUD is required to report.
Overall, RAMPS had the capability to record Recovery Act data and produce the reports…
July 21, 2011
Report
#2011-DP-0007
FY 2010 FISMA
We have completed an audit of the U.S. Department of Housing and Urban Development’s (HUD) information security program. We evaluated whether HUD’s Office of the Chief Information Officer (OCIO) had developed security policies, implemented procedures, and continuously monitored its entitywide information system security program. We performed this audit because it is a required component of our fiscal year 2010 consolidated financial…
February 08, 2011
Report
#2011-DP-0005
Review of HUD's Process for Monitoring Recipient Reporting for the American Recovery and Reinvestment Act of 2009
We audited HUD's process for monitoring recipient reporting for the American Recovery and Reinvestment Act of 2009 (Recovery Act). The Recovery Accountability and Transparency Board (Board), created by the Recovery Act, has required the Inspector General community to evaluate Federal agencies' process for monitoring recipient reporting of Recovery Act funds for the quarter ending September 30, 2009. The audit reports are to be issued to their…
October 29, 2009
Memorandum
#2010-DP-0801
Report on the Review of Recovery Act Management and Reporting System
The HUD Inspector General Office the management procedures, practices, and controls related to the Recovery Act Management and Reporting System (RAMPS) to assess compliance with reporting requirements under the American Recovery and Reinvestment Act (Recovery Act). The audit found that HUD had taken actions to comply with the reporting requirements under the Recovery Act. However, HUD’s effort to implement procedures, practices, and controls…
September 29, 2009
Report
#2009-DP-0008
Review of Selected FHA Major Applications' Information Security Controls
We audited the Federal Housing Administration's (FHA) management of its information technology resources and compliance with U.S. Department of Housing and Urban Development (HUD) and other federal information security requirements. Our overall objective was to determine whether FHA effectively managed security controls relating to its information technology resources. This audit supported our financial statement audits of FHA and HUD as well…
June 11, 2008
Report
#2008-DP-0004
FY 2007 IS controls in support of the financial statements audit (FISCAM)
We reviewed general and application controls for selected information systems to assess management controls over the U.S. Department of Housing and Urban Development's (HUD) computing environments as part of the Office of Inspector General's (OIG) audit of HUD's financial statements for fiscal year 2007 under the Chief Financial Officer's Act of 1990. Our review was based on the Government Accountability Office (GAO) "Federal Information…
March 02, 2008
Report
#2008-DP-0003
Essex County Man Charged with Mortgage Fraud
NEWARK, N.J. – An Essex County, New Jersey, man will be arraigned today on charges that he engaged in a conspiracy to commit mortgage fraud that resulted in potential losses in excess of $1 million, U.S. Attorney Craig Carpenito announced.
Cabral Simpson, 43, of Belleville, New Jersey, appeared before U.S. Magistrate Judge Leda Dunn Wettre in Newark federal court. He is charged by indictment with one count of conspiracy to commit wire fraud…
Press release
January 08, 2020
Two New Jersey Men Sentenced To Prison For Phony Debt Elimination Scheme
NEWARK, N.J. – Two New Jersey men were today sentenced to prison terms for their respective roles in using phony monetary instruments to obtain luxury vehicles and other high value items; one of the defendants was additionally convicted of bankruptcy fraud, U.S. Attorney Craig Carpenito announced.
Germaine Howard King, a/k/a “Germaine Howard,” 47, of Elizabeth, New Jersey, was sentenced to 70 months in prison, and Daniel D. Dxrams, currently…
Press release
January 07, 2020