U.S. flag

An official website of the United States government Here’s how you know

The .gov means it’s official.

Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you're on a federal government site.

The site is secure.

The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

HUD Privacy Program Evaluation Report

Federal organizations have a fundamental responsibility to protect the privacy of individuals and their personally identifiable information (PII) that is collected, used, maintained, shared, and disposed of by agency programs and information systems. The management of U.S. Department of Housing and Urban Development (HUD) programs demands the availability and use of extensive amounts of financial, demographic, and personal information. HUD is entrusted with the PII of millions of individuals.

Federal Information Security Management Act (FISMA) Fiscal Year 2014 Evaluation Report

The Federal Information Security Management Act of 2002 (FISMA) directs the Office of Inspector General (OIG) to conduct an annual evaluation of the U.S. Department of Housing and Urban Development (HUD) information security program.  FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies.

HUD Staff SSN Breach

We have completed a review to determine whether HUD followed proper policies and procedures in responding to a breach of personally identifiable information which occurred on September 21, 2012. Specifically, for this incident, we identified what actions were taken and any deficiencies within HUD policies, plans, or current practices. We determined that HUD responded to the incident properly, following United States Computer Emergency Readiness Team (US-CERT), National Institute of Standards and Technology, and HUD policy and other Federal requirements.

FY 2007 IS controls in support of the financial statements audit (FISCAM)

We reviewed general and application controls for selected information systems to assess management controls over the U.S. Department of Housing and Urban Development's (HUD) computing environments as part of the Office of Inspector General's (OIG) audit of HUD's financial statements for fiscal year 2007 under the Chief Financial Officer's Act of 1990.

FY 2010 FISMA

We have completed an audit of the U.S. Department of Housing and Urban Development’s (HUD) information security program. We evaluated whether HUD’s Office of the Chief Information Officer (OCIO) had developed security policies, implemented procedures, and continuously monitored its entitywide information system security program.

Review of Selected FHA Major Applications' Information Security Controls

We audited the Federal Housing Administration's (FHA) management of its information technology resources and compliance with U.S. Department of Housing and Urban Development (HUD) and other federal information security requirements. Our overall objective was to determine whether FHA effectively managed security controls relating to its information technology resources. This audit supported our financial statement audits of FHA and HUD as well as our annual Federal Information Security Management Act review.

Report on the Review of Recovery Act Management and Reporting System

The HUD Inspector General Office the management procedures, practices, and controls related to the Recovery Act Management and Reporting System (RAMPS) to assess compliance with reporting requirements under the American Recovery and Reinvestment Act (Recovery Act). The audit found that HUD had taken actions to comply with the reporting requirements under the Recovery Act.

Review of HUD's Process for Monitoring Recipient Reporting for the American Recovery and Reinvestment Act of 2009

We audited HUD's process for monitoring recipient reporting for the American Recovery and Reinvestment Act of 2009 (Recovery Act). The Recovery Accountability and Transparency Board (Board), created by the Recovery Act, has required the Inspector General community to evaluate Federal agencies' process for monitoring recipient reporting of Recovery Act funds for the quarter ending September 30, 2009. The audit reports are to be issued to their agencies no later than October 30, 2009.

Review of the National Environmental Policy Act and Core Activity Modules Within the Recovery Act Management and Performance System

We audited the U.S. Department of Housing and Urban Development’s (HUD) management procedures, practices, and controls related to the Recovery Act Management and Reporting System (RAMPS). Our objective was to assess its capability to record and provide data required by the American Recovery and Reinvestment Act of 2009 on which HUD is required to report. Overall, RAMPS had the capability to record Recovery Act data and produce the reports necessary for HUD to comply with the Recovery Act reporting requirements. However, we identified areas in which vulnerabilities existed.