Você está na página 1de 12

2018

SECURITY
PLAN
State of Arizona
Table of Contents
Introduction................................................................................................................................................ 3

Guiding Laws, Procedures and Policies........................................................................................... 4

Layers of Election Security (Figure 1)............................................................................................... 4

Open and Transparent Election Environment.............................................................................. 5

Physical and Personnel Security......................................................................................................... 5


Physical
Personnel

Legal and Procedural Security..............................................................................................................7


Ballot Programming and Election Administration
Logic and Accuracy Tests
Two-Person Rule
Security of Voting Equipment and Ballots to and from the Polls
Early Ballot Tabulation
Post-Election Audits

Technical and System Security............................................................................................................ 8


Split Passwords
Hash Codes
Restrictions
Election Management System (EMS) Specific Restrictions
Audit Logs
Power Supply

Responsibilities........................................................................................................................................10
U.S. Government
Arizona Secretary of State
Pima County Government
Pima County Recorder’s Office
Pima County Elections
Pima County Sheriff’s Department
Pima County Facilities Management
Pima County Information Technology
Pima County Attorney’s Office

Summary....................................................................................................................................................11

2 | Pima County Elections Department Security Plan • July 24, 2018


INTRODUCTION with the elections process. Current security measures
ensure only authorized individuals can access criti-
Security of the voting process is critical to ensur- cal election areas, materials, technical systems and
ing the public’s confidence in elections. The Security ballots. In addition, the Elections Department trains
Plan provides a general overview of tasks as well staff and seasonal employees on the processes and
as roles and responsibilities of selected offices and procedures to ensure the security and integrity of
agencies in maintaining the security of the voting the election process is preserved if a layer becomes
process. compromised, bypassed or proven ineffective. It
also provides a mechanism to detect such failures
Nearly all election systems involve two major so that more effective procedures may be adopted.
independent systems that provide the functionality The contents of this Plan are structured to parallel
for election tabulation and voter registration. In Pima the layers of security from outside in: 1. open and
County, the responsibility for maintaining the voter transparent election environment, 2. physical and 3.
registration system belongs to the Recorder’s Office personnel security, legal and procedural security and
while the responsibility for election tabulation rests technical and systems security.
with the Elections Department. This Security Plan
will focus primarily on security concerns involving This Plan is a living document that will be re-
election tabulation. To manage election tabulation, viewed and updated as significant security issues
Pima County uses the Election Management System arise or situations change. After every election, Elec-
(EMS), which is an operating system comprised of tions staff will review and modify the current pro-
two programs: Elections Systems & Software’s Elec- cess, procedure and systems as needed to improve
tionWare and Elections Systems & Software’s Elec- the effectiveness of the operation and its security. In
tion Reporting Manager. addition to reviewing local outcomes, staff will mon-
itor outcomes from other jurisdictions and examine
The Elections Director or his designee is respon- studies and reviews by third parties. Staff will adjust
sible for coordinating security concerns during the policies and procedures as needed to avoid weak-
elections. That individual is identified to employees nesses experienced or identified by others.
as the primary point of contact for security issues.
All employees directly involved in elections and
Effective security does not depend nor rely on a elections security share the responsibility of ensur-
single process, feature, or policy. It requires a num- ing the County election process remains secure and
ber of interrelated processes, systems, and policies conducted with the utmost integrity. To this end, all
that compliment and build on each other. The sys- new employees must read and become familiar with
tems, processes and policies that comprise the layers the Security Plan as well as any implementation pro-
of security for Pima County Elections are represented cedures relevant to their work areas. Additionally, all
on page 4 in figure 1. employees will be briefed periodically with the key
aspects of this plan.
These multiple layers of security systems, process-
es, and procedures ensure election results are not Election Integrity is the responsibility of every-
inappropriately influenced. By involving external one. Pima County Elections welcomes input from all
stakeholders such as the media, political party ob- employees on ways to improve the security of the
servers, the Arizona Secretary of State and the pub- election process. Similarly, political parties, organi-
lic, the Elections Department offers a level of trans- zations, other observers and the general public can
parency that is integral to the detection of problems suggest ways to enhance system security.

Pima County Elections Department Security Plan • July 24, 2018 | 3


GUIDING LAWS, PROCEDURES, POLICIES • The American Voting Experience: Report and Rec-
AND STUDIES ommendation of the Presidential Commission of
Election Administration January 2014
Laws, procedures, policies and studies that apply • Quick Start Management Guide for Voting System
to elections include: Security, United States Election Assistance Commis-
sion
• Help America Vote Act of 2002 (HAVA): 42 • Center for American Progress: Election Security in
U.S.C. 15301 to 15545 All 50 States February 2018
• Arizona Revised Statutes Title 16 • Belfer Center for Science and International Affairs:
• Arizona Electronic Voting System Instructions and The State and Local Election Cybersecurity Play-
Procedures Manual book February 2018.

LAYERS OF ELECTION SECURITY

Open and Transparent


Elections environment
Physical and
personnel Security
Legal and Procedural
security
Technical and System
Security
Strong Password

Chain of Custody

Key Card Access

Political Party
Integrity and Security of
Surveillance
Two Person

Technology
Encryption
Oversight

Observers
Integrity
groups

Elections is Ensured by
Video

Multiple Security Layers

Media

Law Enforcement
Presence

Auditing

Stand Alone
Tabulation Servers

Figure 1
4 | Pima County Elections Department Security Plan • July 24, 2018
OPEN AND TRANSPARENT ELECTION Public Disclosure of NON-PROTECTED
ENVIRONMENT RECORDS

Administering the elections is a monumental The Elections Department does its best to post
responsibility and one in which openness and information relevant to the general public on its
transparency are essential to gaining and retaining website at www.pima.gov/elections.
the public’s trust in government. It is the process
by which citizens of a democratic republic choose Other departmental records may be requested
their political leaders, and in the State of Arizona, through a Public Records Request sent to the Pima
it is a system in which the electorate through the County Clerk of the Board’s Office.
process of initiative and referenda can directly
make law. In any other system or process, it would Media access
be considered contradictory to require openness
and transparency while at the same time restrict- Who act as additional eyes and ears for the public.
ing access and ensuring strong security, but this is
exactly what election administrators across the na- Video broadcast of ballot tabulation on the web
tion must accomplish. For election administrators,
openness and transparency are defined literally. Pima County Elections Department provides
They involve a variety of concepts that combine streaming video of its ballot tabulation room 24
accountability, accuracy, access, openness, to hours-a-day, seven days a week, year-round via a link
preserve the integrity of the process. Pima County, on the department’s website.
achieves this by:
PHYSICAL AND PERSONNEL SECURITY
Building Infrastructure Design and Access
Physical Security is a layer of defense against un-
Open floor plans, viewing windows, public mon- authorized individuals who may attempt to tamper
itors, exposed and color-coded network wiring, with or harm the election process/personnel. Person-
surveillance cameras and viewing areas are all design nel Security starts with selecting highly trustworthy
elements that facilitate transparency. These ele- individuals and is enhanced through checks and
ments allow the public physical access to the facility balances, which ensure these individuals do not have
and the ability to view the inner workings of the the opportunity or inclination to harm the process.
Elections Department.
Physical
Public/Political Party Observers
Access Control:
The ability for observation of the tabulation With the exception of processes necessary to get
process is grounded in State law and fully embraced the ballots to the voters, the majority of the duties
by the County’s Elections Department. The general performed by the Elections Department are con-
public is encouraged to observe ballot processing ducted in one building. This allows the department
and tabulation. However, for security reasons, this to restrict access and segment work areas. The lobby
must happen from the public viewing area. and public viewing corridor is open to the public.
The election office and work areas, however, have
The chair of the County’s political parties can restricted access. Most doors require electronic key
each nominate observers for their political parties to cards that log the time, date and card number of
vouch for the integrity of the process. These individ- the person who gained access to the restricted area.
uals receive greater access than the general public. In addition, the doors to some restricted areas will
Because the Elections Department is responsible for sound an alarm when the door is left open too long.
the security and integrity of the election, County’s
Elections Director has final say on the assignment of The servers that contain the election management
the observers and can designate where the observ- software receive extra security and are housed in a
ers are stationed. secured environment, a locked and sealed cabinet
Pima County Elections Department Security Plan • July 24, 2018 | 5
inside the tabulation room. When not in use, the Surveillance:
keyboard and mouse are locked and sealed within
the cabinet, and the network cables for the servers Forty-seven video surveillance cameras are set up
are disconnected. A log is maintained to record seal at strategic locations to provide staff with the ability
numbers and access to the interior of the cabinet. to observe restricted areas inside and outside of the
facility. Video recordings remain archived for five
This secured, locked room serves as the location months, one year or two years depending on the
where the election database is prepared and where cameras location and/or function. In most cases, the
ballot layout and design is performed. Access is length of the archive depends on the level of securi-
given only to qualified and authorized personnel. All ty of the location. Streaming video of the tabulation
persons, with the exception of select County Elec- room is available through a link on the Elections
tions employees, entering the tabulation area must Department website.
sign a manual log stating time in/out and the pur-
pose of their visit. Security cameras continuously monitor the front
and rear of the Election Management System’s server
Accessible voting devices are stored in a secured cabinet to record any access, attempted access or
limited access room within the facility. Voter access, attempt to shut down the system.
supervisor and administrator cards for the accessible
voting units in addition to memory cards containing Each level of security generates a log of activity.
the programs for each unit are secured in a locked If a level of security fails, the log can detect who
safe until they are installed into the device. The outer may have tampered with a device and when it likely
case of each of these units is sealed with a minimum occurred.
of two uniquely numbered, tamper-evident seals.
Each of the units and the associated components Personnel
are tracked with an electronic inventory system to
maintain a documented chain of custody. Only authorized personnel with a specific need for
access can enter sensitive areas. All personnel, ob-
Servers and Electronic Media: servers and visitors in the Elections Center must wear
visible credentials at all times. Elections Department
All sensitive equipment, media and supplies are personnel are trained to stop and question anyone
secured in locked cabinets and/or fire proof safes without proper credentials. Non-county employees
contained in a controlled access room, which is must be accompanied by an escort at all times.
under video surveillance 24 hours-a-day, seven days
a week. Employee and observers who work during elec-
tions must practice a high level of security. County
Uniformed Security Presence: Employees must read and agree to follow Pima
County policies and procedures when hired or reac-
Pima County Elections works with the Pima Coun- tivated.
ty Sheriff’s Department to assign commissioned
law enforcement officers in uniform to the Elections Upon the implementation of this plan, back-
Center at times of heightened security. Officers are ground checks will be required for all employees and
stationed at key locations where they can protect observers who work in areas of heightened securi-
access points and act as additional observers of the ty. The Elections Director identifies and designates
processes, staff and visitors. heightened security areas.

6 | Pima County Elections Department Security Plan • July 24, 2018


LEGAL AND PROCEDURAL SECURITY After passing the official L&A, a copy of the elec-
tion definition and database is saved onto a portable
Ballot Programming and Election Administration media device and given to the Arizona Secretary of
State’s Office as a backup of the election at the time
The Elections Department is responsible for the of testing.
programming of all elections administered in Pima
County. Information Technology staff and vendors Two-Person Rule
may be asked to resolve problems with hardware or
software but only elections staff may program the To prevent the possibility of illegal manipulation
election or know the election specific passwords. of voted ballots, any time voted ballots are not in
The process of election programing and ballot layout a sealed container, they shall be in the presence of
takes place in the tabulation room under camera sur- no fewer than two observers from different political
veillance with controlled and tracked access to the parties.
room.
Additionally, the two-person rule is extended to
Logic and Accuracy Tests operations in the tabulation room.

Before every election, the entire vote tabulation sys- Anytime the server is unlocked and unsealed,
tem undergoes rigorous logic and accuracy testing. there must be at least two Elections Department
The process verifies each machine properly counts, employees present in the room. If there are voted
records and tabulates results correctly. The tabulation ballots in the room, political party observers must be
system must pass logic and accuracy testing before it present as well.
is “set” for the election. Typically, the tabulation sys-
tem undergoes three Logic and Accuracy (L&A) tests: The County Elections Director may assign observ-
In-house, Party, and Secretary of State (SOS). ers in pairs at times other than prescribed above as
the director deems necessary. Ballot processing shall
In the In-house L&A, a test deck of ballots is not be curtailed if the requested observers have not
marked so that every candidate/option in every been provided.
race is marked at least once. Each race is over voted
and under voted. Ballots are processed through the Security of Voting Equipment and Ballots to and
tabulation system and a results report is printed. The from the Polls
test results are compared with the expected results.
If the test results match, the test is successful. Pima County utilizes numbered tamper-evident
seals on all voting equipment and ballot storage
In the Party L&A, political party observers mark devices. Tamper-evident numbered seals are affixed
test ballots. The ballots are processed and the results across the seam of the two halves of the exterior case
reported. Political party observers then compare the of the ADA accessible voting device. The slots/doors
test results with their expected results. The test is for the flash memory cards are also sealed. The condi-
successful if the political party observers determine tion of the seals and seal numbers must be verified by
the ballots tabulated correctly. at least two election officials at the polls prior to the
start of voting. In addition, Pima County maintains a
In the SOS L&A, the Arizona Secretary of State’s written log that records each seal number assigned to
technical staff mark ballots. each voting unit. Any breach of control over a sealed
item requires immediate notification to Pima County
These ballots are processed and the results re- Elections.
ported. The State’s technical staff compares the test
results with the expected results. If the results match, After the polls close, one poll worker from each
the test is successful. If the election includes candi- party returns the tablet from the ADA accessible vot-
dates for federal or state offices or a statewide ballot ing equipment and voted ballots in sealed/numbered
question, the SOS L&A is the official logic and accura- containers to a receiving center. At each receiving
cy test used. center, the numbered seals get checked once more
Pima County Elections Department Security Plan • July 24, 2018 | 7
and a receipt is issued to the poll workers. If the seals may choose to perform hand count/audits for local
have been damaged or the numbers do not match, elections to increase voter confidence. The politi-
the poll workers must make a statement explaining cal parties and civic groups will be encouraged to
the discrepancy. That statement will be added to the observe and participate in the process. Additionally,
receipt before it’s issued to the poll workers. state law does not provide for other post-election
audits, but the County may choose to perform other
From the receiving centers, the equipment is audits to increase voter awareness and confidence in
returned to the Election Department where the seals the election process.
are checked again under political party observation.
Election employees assigned to tabulate votes will TECHNICAL AND SYSTEM SECURITY
also check the seals before processing the votes
from the machines. Technical security features include the comput-
er security components necessary to ensure data
Early Ballot Tabulation integrity and security of technical systems, and
prevent unauthorized access into election systems
The tabulation of early ballots can begin no by using best practice tools, processes, procedures
sooner than seven days prior to Election Day. Early and policies. Proper management of the technical
ballots are tabulated under public and/or political security environment of the system is critical to
party observation. Political parties will be notified prevent any unauthorized access to elections sys-
in advance on the date and time of early ballot tems and data, even if an unauthorized individual
processing. Unless approved by the Elections has circumvented other layers of security. Technical
Director or designee, only one observer from each security is the last barrier to someone intenting
political party is allowed in the counting room at malicious action, though the other layers of secu-
any time. rity would facilitate detection (e.g. armed Sheriff’s
deputy security, camera surveillance and key card
During the administration of partisan elections, access records).
political party representatives designate batches of
early ballots subject to hand count audit prior to offi- Split passwords
cial canvass of the election. By law, summary reports
are generated for each batch of ballots selected by Election staff members responsible for election
the political parties. The generation of summary re- programming cannot access the tabulation com-
ports, other than those prescribed by law, is prohibit- puter without a proper password. The password
ed. A brightly colored sheet of paper is placed on the is in two parts and no staff member knows both.
printer before and after each summary is printed so A maximum of two staff members know the first
that the equipment operator will not see any elec- part and a maximum of two staff members know
tion results. the second. The complete password must be at
least sixteen characters long and comprised of a
Post-Election Audits mix of case sensitive letters, numbers and sym-
bols.
Audits are preformed to check the accuracy of the
system and to catch fraud or mistakes. Once staff members gain access to the election
Arizona State Law requires a hand count/audit program, they must enter an additional password
of ballots from randomly selected precincts and to access the Election Management System. A maxi-
early ballot batches for the presidential preference, mum of four staff members know the password. The
primary and general elections. By law, the audited password shall be at least sixteen characters long
ballots and contests are randomly selected by the and may be comprised of a mix of case sensitive
political parties and the entire auditing process is letters, numbers and symbols.
open to political party observation and participa-
tion. Passwords are changed at least once a year. As
State law does not provide for the hand count/ best practices for passwords change so will the pass-
audits for local elections. However, Pima County word requirements.
8 | Pima County Elections Department Security Plan • July 24, 2018
Hash Codes Election Management System (EMS) Specific
Restrictions:
A hash code is a large number called a “message
digest”. The large number is computed using a stan- The ballot tabulation equipment and software are
dard algorithm that is applied to the entire string of the most secure systems used by Pima County Elec-
bits that makeup a file. The algorithm is designed so tions and are housed in a single room with height-
that the changing of one bit in the file will result in a ened security features. Access to this room is signifi-
completely different message digest. cantly restricted. ElectionWare is the software used to
define the election, design ballots and program soft-
Hash code testing involves applying the algorithm ware for the central count tabulators. Election Report-
to the file tested and generating a message digest. ing Media is the software used to aggregate results of
This test value is compared to the original value early ballots, polls and provisional ballots counted by
generated when the algorithm was applied to the the central count tabulators. It’s also used to generate
certified file. If the values match, the file has passed reports. This software is installed on two servers (one
the test and the file is accepted as unaltered. Hash primary and one backup) and is solely administered
code testing validates the ballot tabulation execut- by Elections Department personnel.
able software is exactly the same software tested
and analyzed in the federal and state certification The EMS software is installed on a wired local area
process. network that is physically contained within the tabu-
lation room. This network connects the two servers,
The County’s Information Technology Department two workstations, six tabulators and one printer.
conducts the hash code testing and certifies the Connecting to any outside network or wireless device
software as unaltered for the Elections Department. is prohibited. This “air gapped,” “closed” system has
no connectivity to the Internet. Because of that, there
Before installing or upgrading software on any is no way the County voting tabulation system can be
system involved with collection and tabulation of hacked without having physical access to the system.
votes, Pima County Elections verifies the software Data sharing with other networked devices is through
received matches the one certified at the federal and use of pristine CD, DVD or Blu-Ray disks burned as
state levels by hash code testing. read only devices.

Prior to each election, additional hash code testing To ensure the security and integrity of tabulated
is conducted on the ballot tabulation executables results, additional steps are taken when interruption
software to verify the software has not been altered. in tabulation occurs. Prior to the start of tabulation,
a zero report is produced from each of the ballot
Restrictions tabulators and the reporting software. This ensures
all races start at zero and certifies no ballots have
No wireless devices will be used or attached to been processed. When breaking for lunch or the day,
any component of the Election each tabulator and the reporting software produces
a report on the ballots processed. Before resuming
Management System including tabulation devices, the ballots process again, another set of reports is
workstations or servers. Pima County employs wire- generated. Elections staff and political party observers
less sniffers 24 hours-a-day, seven days a week, at the compare the reports to ensure no additional ballots
Election Center to detect signals. were processed during the break. Party observers
must sign and date the reports to certify there was no
Additionally, Pima County Elections does not use change.
precinct scanners. Voted ballots are placed in a se-
cured/sealed ballot box. The ADA accessible device is When possible, the ballot tabulators get cleared at
only used as a ballot-marking device. The voter ver- the end of each day’s tabulation so that zero reports
ified tape is used to duplicate ballots for tabulation. can be produced at the end and beginning of each
Ballot tabulation is restricted to the central count fa- day’s tabulation. Additionally, the election database
cility; no tabulation is conducted at the polling place. on the server gets backed up. A copy of the database
Pima County Elections Department Security Plan • July 24, 2018 | 9
is stored on the secondary server and on an encrypt- RESPONSIBILITIES
ed USB thumb drive, which gets stored in the tabula-
tion room safe. Elections require participation and responsibility
at all levels of government. A list of responsibilities
Audit Logs below is not intended to be exhaustive, but does
provide an overview for various aspects of the elec-
Continuous audit logs are produced by each of tion process.
the ballot tabulators and workstations.
U.S. Government – Provides certification of voting
A copy of the workstation’s audit log is printed tabulation systems.
and provided to the party observers. This will act
as a baseline for activity on the workstation. At the Arizona Secretary of State – Provides procedures
beginning and end of each day’s tabulation, a copy and advisories; state certification of voting tabulation
of the audit log is provided to the party observers so systems; and performs pre-election testing of the
they can verify there was no activity on the worksta- tabulation system.
tions while on break during tabulation.
Pima County Government – Oversees federal, state
The audit logs created by the ballot tabulators and local elections for Pima County.
are printed on line printers that update the logs in
real time. The line printers are loaded with tractor Pima County Recorder’s Office – Maintains the
fed continuous sheets of paper. If there is a break in Pima County list of registered voters, administers
the paper, both the end of the old page and start early voting and validates early ballots.
of the new page must be signed by the available
party observers and at least one County employee. Pima County Elections – On behalf of the Pima
These logs are available for inspection by the party County Board of Supervisors, administers all federal,
observers at all times while in the tabulation room. state and local elections in Pima County.
These logs are detached from the printers at the end
of each calendar year and stored for six to 24 months Pima County Sheriff’s Department – Provides
depending on the type of election administered security at Pima County Election facilities and
during that year. provides deputies to act as couriers for election
material(s) on Election Night.
Power Supply
Pima County Facilities Management – Provides
Each major component of the Election Manage- security enhancements in Pima County facilities used
ment System, which includes servers, workstations for election tabulation.
and tabulators, is protected by an uninterruptible
power supply (UPS) to ensure an orderly shutdown of Pima County Information Technology – Assists
the equipment. If the power to the tabulation room with hash code check(s), video surveillance and
is interrupted, the UPS will provide enough power to provides cyber security.
produce the required reports and safely turn off the
equipment. The UPS gets tested a minimum of two Pima County Attorney’s Office – Provides legal
times per year. counsel.

10 | Pima County Elections Department Security Plan • July 24, 2018


SUMMARY This Security Plan details many safeguards in place
to protect elections in Pima County. Many of the safe-
Effective security does not rely on a single process, guards are not unique to Pima County Elections and
feature or policy. Effective security requires a num- are deployed throughout election agencies across the
ber of interrelated processes, systems and policies to state and country. Many of the safeguards in place
compliment and build on each other. The systems, today were implemented before they became rec-
processes and policies that comprise layers of security ognized as best practices. They are based on lessons
for Pima County Elections are represented in detail learned internally, through observation of others or
throughout this plan and illustrated graphically on through legal requirements.
page 5, Figure 1.
The security of elections in Pima County is also the
These multiple layers of security systems, processes result of a genuine commitment by election offi-
and procedures ensure election results are not inap- cials to cooperate with outside stakeholders. Local
propriately influenced. External stakeholders such as stakeholder recommendations for improvement
the media, candidates, political parties, the Arizona have proven beneficial and been adopted into the
Secretary of State and members of the public pro- process. The Elections Department is receptive to
vide transparency and are integral to the detection recommendations made by all interested parties that
of problems with the election process. The physical contribute to election security, election integrity,
and personnel security measures, which have been public trust, openness, transparency and account-
implemented, ensure only authorized individuals ability.
have access to critical election spaces, materials,
technical systems and ballots. Election staff members Election administrators and public officials contin-
receive trained in election processes and procedures ue to implement and improve safeguards to protect
designed to protect the security and integrity of the the integrity of elections, as all share responsibility
election process. Additionally, the elections process- for protecting the process. A key element to improv-
es are audited and reviewed throughout with many ing election security is the participation of voters,
check points for accuracy. The layered approach en- state and local officials, political parties and other
sures the security and integrity of the election process stakeholders working in tandem with election offi-
is preserved if one or two layers are compromised, cials to identify threats and areas of opportunity for
bypassed or proven ineffective. improvement.

Pima County Elections Department Security Plan • July 24, 2018 | 11


6550 S. Country Club Road
Tucson, AZ 85756
(520) 724-6830
www.pima.gov/elections

12 | Pima County Elections Department Security Plan • July 24, 2018

Você também pode gostar