World Video | Defence | Foreign Affairs | Natural Events | Trade | NZ in World News | NZ National News Video | NZ Regional News | Search


SAIC Report On MD. Diebold Voting Machines

SAIC Report On MD. Diebold Voting Machines


This report presents the results of a risk assessment of the AccuVote-TS voting system as currently implemented in Maryland by the State Board of Elections (SBE) and the Local Boards of Elections (LBEs). This Risk Assessment report includes evaluations of threats, vulnerabilities, security controls, and risks associated with the AccuVote-TS system and possible impacts to the State and the integrity of its elections process from successful exploitation of identified weaknesses.

This Risk Assessment was performed using the methodology documented in National Institute of Science and Technology (NIST) SP 800-30, Risk Management Guide for Information Technology Systems, and in the State of Maryland’s Certification and Accreditation Guidelines. This assessment consists of agency-directed, independent verification of systems, software, and processes associated with the system. This assessment provides an in-depth analysis of security controls, including comprehensive personnel interviews, documentation reviews, site surveys, and evaluation of the system’s hardware and software. Overall, this assessment measures the level of assurance that the security controls for the system are fully formed and documented, correctly implemented, and effective in their application.

Findings & Recommendations

In the course of this Risk Assessment, we reviewed the statements that were made by Aviel. D. Rubin, professor at Johns Hopkins University, in his report dated July 23, 2003. In general, SAIC made many of the same observations, when considering only the source code. While many of the statements made by Mr. Rubin were technically correct, it is clear that Mr. Rubin did not have a complete understanding of the State of Maryland’s implementation of the AccuVote-TS voting system, and the election process controls or environment. It must be noted that Mr. Rubin states this fact several times in his report and he further identifies the assumptions that he used to reach his conclusions. The State of Maryland procedural controls and general voting environment reduce or eliminate many of the vulnerabilities identified in the Rubin report. However, these controls, while sufficient to help mitigate the weaknesses identified in the July 23 report, do not, in many cases meet the standard of best practice or the State of Maryland Security Policy.

This Risk Assessment has identified several high-risk vulnerabilities in the implementation of the managerial, operational, and technical controls for AccuVote-TS voting system. If these vulnerabilities are exploited, significant impact could occur on the accuracy, integrity, and availability of election results. In addition, successful exploitation of these vulnerabilities could also damage the reputation and interests of the SBE and the LBEs. This Risk Assessment also identified numerous vulnerabilities with a risk rating of medium and low that may have an impact upon AccuVote-TS voting if exploited.

This assessment of the current security controls within the AccuVote-TS voting system is dependent upon the system being isolated from any network connections. If any of the AccuVote-TS voting system components, as presently configured and architected, were connected to a network, the risk rating would immediately be raised to high for several of the identified vulnerabilities. SAIC recommends that a new risk assessment be performed prior to the implementation of a major change to the AccuVote-TS voting system. Additionally, SAIC recommends a similar assessment to be performed at least every three years, regardless of system modification.

We recommend that SBE immediately implement the following mitigation strategies to address the identified risks with a rating of high:

1. Bring the AccuVote-TS voting system into compliance with the State of Maryland Information Security Policy and Standards.
2. Consider the creation of a Chief Information Systems Security Officer (CISSO) position at SBE. This individual would be responsible for the secure operations of the AccuVote-TS voting system.
3. Develop a formal, documented, complete, and integrated set of standard policies and procedures. Apply these standard policies and procedures consistently through the LBEs in all jurisdictions.
4. Create a formal, System Security Plan. The plan should be consistent with the State of Maryland Information Security Policy and Standards, Code of Maryland Regulations (COMAR), Federal Election Commission (FEC) standards, and industry best practices.
5. Apply cryptographic protocols to protect transmission of vote tallies.
6. Require 100 percent verification of results transmitted to the media through separate count of PCMCIA cards containing the original votes cast.
7. Establish a formal process requiring the review of audit trails at both the application and operating system levels.
8. Provide formal information security awareness, training, and education program appropriate to each user’s level of access.
9. Review any system modifications through a formal, documented, risk assessment process to ensure that changes do not negate existing security controls. Perform a formal risk assessment following any major system modifications, or at least every three years.
10. Implement a formal, documented process to detect and respond to unauthorized transaction attempts by authorized and/or unauthorized users.
11. Establish a formal, documented set of procedures describing how the general support system identifies access to the system.
12. Change default passwords and passwords printed in documentation immediately.
13. Verify through established procedures that the ITA-certified version of software and firmware is loaded prior to product implementation.
14. Remove the SBE GEMS server immediately from any network connections. Rebuild the server from trusted media to assure and validate that the system has not been compromised. Remove all extraneous software not required for AccuVote-TS operation. Move the server to a secure location.
15. Modify procedures for the Logic and Accuracy (L&A) testing to include testing of time-oriented exploits (e.g., Trojans).
16. Discontinue the use of an FTP server to distribute the approved ballots.
17. Implement an iterative process to ensure that the integrity of the AccuVote-TS voting system is maintained throughout the lifecycle process.

The system, as implemented in policy, procedure, and technology, is at high risk of compromise. Application of the listed mitigations will reduce the risk to the system. Any computerized voting system implemented using the present set of policies and procedures would require these same mitigations.


© Scoop Media

World Headlines


IPPPR: The Independent Panel Calls For Urgent Reform Of Pandemic Prevention And Response Systems

Expert independent panel calls for urgent reform of pandemic prevention and response systems The Independent Panel for Pandemic Preparedness and Response is today calling on the global community to end the COVID-19 pandemic and adopt a series of bold and ... More>>

NGO Coalition On Human Rights: Call For A Stop To Police Brutality In Fiji

A viral video has circulated online showing two police officers utilising disproportionate and excessive force in detaining the suspect, an individual half their size. In the video it shows the man’s head being pressed down on the ground, his arms being ... More>>

UN: India’s New COVID-19 Wave Is Spreading Like ‘Wildfire’, Warns UN Children’s Fund

7 May 2021 A new wave of COVID-19 infections is spreading like “wildfire” across India, leaving many youngsters destitute, the UN Children’s Fund UNICEF said on Friday. In the last 24 hours, India registered 3,915 coronavirus deaths and 414,188 ... More>>

Focus On: UN SDGs

UN: Economic Recovery Under Threat Amid Surging COVID Cases And Lagging Vaccination In Poorer Countries

New York, 11 May — While the global growth outlook has improved, led by robust rebound in China and the United States, surging COVID-19 infections and inadequate vaccination progress in many countries threaten a broad-based recovery of the world ... More>>

Study: Cut Methane Emissions To Avert Global Temperature Rise

6 May 2021 Methane emissions caused by human activity can be reduced by up to 45 per cent this decade, thus helping to keep global temperature rise to 1.5 degrees Celsius in line with the Paris Agreement on climate change, according to a UN-backed ... More>>

UN: Learning From COVID-19, Forum To Highlight Critical Role Of Science, Technology And Innovation In Global Challenges

New York, 4 May —To build on the bold innovations in science, technology and innovations that produced life-saving solutions during the COVID-19 pandemic, the UN will bring together experts to highlight measures that can broaden the development and deployment ... More>>