8.16: Difference between revisions

From Arizona Citizen Voice
No edit summary
 
(2 intermediate revisions by the same user not shown)
Line 7: Line 7:
'''>>>Navigational Buttons<<<'''
'''>>>Navigational Buttons<<<'''
* '''[[Index of Attributes]]'''
* '''[[Index of Attributes]]'''
* '''Previous Attribute - '''
* '''Previous Attribute - [[8.15]]'''
* '''Next Attribute - ?'''
* '''Next Attribute - [[8.17]]'''
__FORCETOC__
__FORCETOC__


=== '''No Examples''' ===
=== Jamie's Story ===
No examples are available to illustrate governance gaps for this attribute.
 
=== Election Anomalies ===
The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.
 
The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.
 
===== Arizona Senate Allegations =====
Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the Arizona Attorney General's Office 2020 General Election Investigation. This Green Book attribute applies given the Arizona Senate's concern that the 2020 election results may have been fraudulently reported, The following allegations relate to the potential for external entities to access the MC election-related IT equipement.
 
* [[The Anomalies#Maricopa Election Management Server (2020)|Maricopa Election Management Server (2020)]]
** [[The Anomalies#MC EMS 2020 - Failure to Follow Basic Cyber Security Practices|MC EMS 2020 - Failure to Follow Basic Cyber Security Practices]]
** [[The Anomalies#MC EMS 2020 - Anonymous Logins|MC EMS 2020 - Anonymous Logins]]
** [[The Anomalies#MC EMS 2020 - Dual Boot System Discovered|MC EMS 2020 - Dual Boot System Discovered]]
** [[The Anomalies#MC EMS 2020 - Operating System Logs Not Preserved|MC EMS 2020 - Operating System Logs Not Preserved]]
** [[The Anomalies#MC EMS 2020 - Internet Connections to the EMS|MC EMS 2020 - Internet Connections to the EMS]]

Latest revision as of 16:01, 27 August 2026

Risk Assessment

Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk

Attribute 8.16 - External risks may come from external parties that connect with or operate the entity's information technology or from unrelated attackers. External parties that connect with the entity's operating systems and databases in the normal course of operations may include end users, such as program beneficiaries; federal, state, and local government entities; and service organizations. External parties that operate the entity's information technology may include developers to which the entity outsources the design of information technology or service organizations or location-independent technology services that operate the systems on behalf of the entity. External information security risks may arise when an entity relies on these external parties' internal control systems as they perform business processes for the entity.

>>>Navigational Buttons<<<


Jamie's Story

No examples are available to illustrate governance gaps for this attribute.

Election Anomalies

The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.

The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.

Arizona Senate Allegations

Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the Arizona Attorney General's Office 2020 General Election Investigation. This Green Book attribute applies given the Arizona Senate's concern that the 2020 election results may have been fraudulently reported, The following allegations relate to the potential for external entities to access the MC election-related IT equipement.