11.02: Difference between revisions
No edit summary |
|||
| (2 intermediate revisions by the same user not shown) | |||
| Line 16: | Line 16: | ||
=== Election Anomalies === | === Election Anomalies === | ||
===== Arizona Senate Allegations ===== | |||
Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation]. The Arizona Senate's concerns relate to the following Green Book statement, "Information security is the protection of information or information technology from unauthorized access, use, disclosure, disruption, modification, or destruction to provide confidentiality, integrity, and availability." | |||
* [[The Anomalies#Maricopa Election Management Server (2020)|Maricopa Election Management Server (2020)]] | |||
** [[The Anomalies#MC EMS 2020 - Election Management System Database Purged|MC EMS 2020 - Election Management System Database Purged]] | |||
** [[The Anomalies#MC EMS 2020 - Election Files Deleted|MC EMS 2020 - Election Files Deleted]] | |||
** [[The Anomalies#MC EMS 2020 - Corrupt Ballot Images|MC EMS 2020 - Corrupt Ballot Images]] | |||
** [[The Anomalies#MC EMS 2020 - Missing Ballot Images|MC EMS 2020 - Missing Ballot Images]] | |||
** [[The Anomalies#MC EMS 2020 - Failure to Follow Basic Cyber Security Practices|MC EMS 2020 - Failure to Follow Basic Cyber Security Practices]] | |||
** [[The Anomalies#MC EMS 2020 - Subpoenaed Equipment Not Yet Provided|MC EMS 2020 - Subpoenaed Equipment Not Yet Provided]] | |||
** [[The Anomalies#MC EMS 2020 - Anonymous Logins|MC EMS 2020 - Anonymous Logins]] | |||
** [[The Anomalies#MC EMS 2020 - Dual Boot System Discovered|MC EMS 2020 - Dual Boot System Discovered]] | |||
** [[The Anomalies#MC EMS 2020 - Operating System Logs Not Preserved|MC EMS 2020 - Operating System Logs Not Preserved]] | |||
** [[The Anomalies#MC EMS 2020 - Internet Connections to the EMS|MC EMS 2020 - Internet Connections to the EMS]] | |||
===== [[Dropbox Collection (2020)|Maricopa Dropbox Collection (2020)]] ===== | |||
Governance issues identified from [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation] of Arizona Senate allegations of Maricopa County Election Department - Drop Box Collections issues. | |||
MC's voter registration database was not included in this Section 2 investigation of Drop Box issues. However, the consequences of a poorly maintained and corrupted database were identified by the AZ AG's inspector. See the heading [[Dropbox Collection (2020)#Deviation: Fictious Addresses in the MC Voter Registration Database|Deviation: Fictious Addresses in MC Voter Registration Database]] from Maricopa Dropbox Collection (2020) webpage for an assessment of over 56,000 undeliverable early ballots. These early ballots under USPS control may be stolen and used for fraudulent purposes given that they are treated as first-class mail, not as valid ballots with potential to sway elections. The information within the MC Voter Registration database has been corrupted. | |||
This attribute, 11.02 also discusses controls to mitigate risks to information security. The AZ AG's inspector's interview with the USPS inspector reveals a significant vulnerability with respect of the USPS's effort to update Maricopa County and Runbeck Election Services with the list of undeliverable early ballots. See the heading [[Dropbox Collection (2020)#Noteworthy: Transmission of USPS Data to MC and Runbeck|Noteworthy: Transmission of USPS Data to MC and Runbeck]] from Maricopa Dropbox Collection (2020) webpage. The USPS inspector describes the transfer of a list (singular) of scanned early ballots that were undeliverable. By the AZ AG's inspector's report, the USPS inspector asserts that this will prevent their tabulation and the Voter Registration database can be corrected. There are numerous concerns with the USPS account, which are as follows: | |||
* A single list of undeliverable ballots would not have been compiled until all the early ballots had been received by the USPS, which most certainly would have been after the election had been closed. If true, the USPS assertion that the list would prevent fraud by rendering the ballot invalid is illogical. All of the fraudulent ballots would have been tabulated before MC received the list of 56,266 undeliverable early ballots. | |||
* The USPS does not explain the chain of custody that should exist between a USPS employee that is accountable for the list and a MC employee that receives the list, plus another MC employee that attests to the invalidation of the registered voters with invalid addresses. | |||
* The USPS does not explain information security, which should ensure the list only contains undelivered addresses, and it has not been corrupted to include valid addresses to valid voters.  | |||
* The USPS describes the delivery of the list to MC and Runbeck Election services. The distribution of data to two different recipients compromises data security. How can two different databases be expected to be the same if data is inputted separately?  | |||
* Under what authority is USPS permitted to share data that belongs to MC to a third-party entity, such as Runbeck Election Services. | |||
Latest revision as of 17:06, 27 August 2026
Control Activities
Principle 11 - Design General Control Activities over Information Technology
Attribute 11.02 - Management designs general control activities over the entity's information technology to mitigate risks to information security. Information security is the protection of information or information technology from unauthorized access, use, disclosure, disruption, modification, or destruction to provide confidentiality, integrity, and availability. The reliability of information technology used within business processes, including automated controls, depends on the selection, development, and implementation of general control activities over information technology.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - 11.01
- Next Attribute - 11.03
Jamie's Story
No examples are available to illustrate governance gaps for this attribute.
Election Anomalies
Arizona Senate Allegations
Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the Arizona Attorney General's Office 2020 General Election Investigation. The Arizona Senate's concerns relate to the following Green Book statement, "Information security is the protection of information or information technology from unauthorized access, use, disclosure, disruption, modification, or destruction to provide confidentiality, integrity, and availability."
- Maricopa Election Management Server (2020)
- MC EMS 2020 - Election Management System Database Purged
- MC EMS 2020 - Election Files Deleted
- MC EMS 2020 - Corrupt Ballot Images
- MC EMS 2020 - Missing Ballot Images
- MC EMS 2020 - Failure to Follow Basic Cyber Security Practices
- MC EMS 2020 - Subpoenaed Equipment Not Yet Provided
- MC EMS 2020 - Anonymous Logins
- MC EMS 2020 - Dual Boot System Discovered
- MC EMS 2020 - Operating System Logs Not Preserved
- MC EMS 2020 - Internet Connections to the EMS
Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County Election Department - Drop Box Collections issues.
MC's voter registration database was not included in this Section 2 investigation of Drop Box issues. However, the consequences of a poorly maintained and corrupted database were identified by the AZ AG's inspector. See the heading Deviation: Fictious Addresses in MC Voter Registration Database from Maricopa Dropbox Collection (2020) webpage for an assessment of over 56,000 undeliverable early ballots. These early ballots under USPS control may be stolen and used for fraudulent purposes given that they are treated as first-class mail, not as valid ballots with potential to sway elections. The information within the MC Voter Registration database has been corrupted.
This attribute, 11.02 also discusses controls to mitigate risks to information security. The AZ AG's inspector's interview with the USPS inspector reveals a significant vulnerability with respect of the USPS's effort to update Maricopa County and Runbeck Election Services with the list of undeliverable early ballots. See the heading Noteworthy: Transmission of USPS Data to MC and Runbeck from Maricopa Dropbox Collection (2020) webpage. The USPS inspector describes the transfer of a list (singular) of scanned early ballots that were undeliverable. By the AZ AG's inspector's report, the USPS inspector asserts that this will prevent their tabulation and the Voter Registration database can be corrected. There are numerous concerns with the USPS account, which are as follows:
- A single list of undeliverable ballots would not have been compiled until all the early ballots had been received by the USPS, which most certainly would have been after the election had been closed. If true, the USPS assertion that the list would prevent fraud by rendering the ballot invalid is illogical. All of the fraudulent ballots would have been tabulated before MC received the list of 56,266 undeliverable early ballots.
- The USPS does not explain the chain of custody that should exist between a USPS employee that is accountable for the list and a MC employee that receives the list, plus another MC employee that attests to the invalidation of the registered voters with invalid addresses.
- The USPS does not explain information security, which should ensure the list only contains undelivered addresses, and it has not been corrupted to include valid addresses to valid voters. 
- The USPS describes the delivery of the list to MC and Runbeck Election services. The distribution of data to two different recipients compromises data security. How can two different databases be expected to be the same if data is inputted separately? 
- Under what authority is USPS permitted to share data that belongs to MC to a third-party entity, such as Runbeck Election Services.
