11.07: Difference between revisions
Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.07''' - Management designs appropriate types of general control activities to mitigate information security risks. General control activities are the actions established through policies and procedures that apply to all or a large segment of an entity's information technology. They support the proper operation of the entity's information technol..." |
|||
| (4 intermediate revisions by the same user not shown) | |||
| Line 3: | Line 3: | ||
'''Principle 11 - Design General Control Activities over Information Technology''' | '''Principle 11 - Design General Control Activities over Information Technology''' | ||
'''Attribute 11.07''' - | '''Attribute 11.07''' - Management designs appropriate types of general control activities to mitigate information security risks. General control activities are the actions established through policies and procedures that apply to all or a large segment of an entity's information technology. They support the proper operation of the entity's information technology by creating a suitable environment for effective operation of application and user control activities. When designing general control activities, management evaluates information security objectives to meet the defined information requirements. General control activities are designed to achieve one or more of the following information security objectives: | ||
Management designs appropriate types of general control activities to mitigate information security risks. General control activities are the actions established through policies and procedures that apply to all or a large segment of an entity's information technology. They support the proper operation of the entity's information technology by creating a suitable environment for effective operation of application and user control activities. When designing general control activities, management evaluates information security objectives to meet the defined information requirements. General control activities are designed to achieve one or more of the following information security objectives: | |||
* '''Confidentiality''' - Preserving authorized restrictions on information access and disclosure, including means for protecting privacy and sensitive information. | * '''Confidentiality''' - Preserving authorized restrictions on information access and disclosure, including means for protecting privacy and sensitive information. | ||
* '''Integrity''' - Guarding against improper information modification or destruction, which includes ensuring information's nonrepudiation and authenticity. | * '''Integrity''' - Guarding against improper information modification or destruction, which includes ensuring information's nonrepudiation and authenticity. | ||
* '''Availability''' - Ensuring timely and reliable access to and use of information, thus preventing the disruption of access to or use of information or information technology. | * '''Availability''' - Ensuring timely and reliable access to and use of information, thus preventing the disruption of access to or use of information or information technology. | ||
'''>>>Navigational Buttons<<<''' | |||
* '''[[Index of Attributes]]''' | |||
* '''Previous Attribute - [[11.06]]''' | |||
* '''Next Attribute - [[11.08]]''' | |||
__FORCETOC__ | |||
=== Jamie's Story === | |||
No examples are available to illustrate governance gaps for this attribute. | |||
=== Election Anomalies === | |||
===== Arizona Senate Allegations ===== | |||
Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation]. This Green Book attribute applies given the Arizona Senate's concern that the 2020 election related to the integrity of the data. | |||
* [[The Anomalies#Maricopa Election Management Server (2020)|Maricopa Election Management Server (2020)]] | |||
** [[The Anomalies#MC EMS 2020 - Election Management System Database Purged|MC EMS 2020 - Election Management System Database Purged]] | |||
** [[The Anomalies#MC EMS 2020 - Election Files Deleted|MC EMS 2020 - Election Files Deleted]] | |||
** [[The Anomalies#MC EMS 2020 - Corrupt Ballot Images|MC EMS 2020 - Corrupt Ballot Images]] | |||
** [[The Anomalies#MC EMS 2020 - Missing Ballot Images|MC EMS 2020 - Missing Ballot Images]] | |||
** [[The Anomalies#MC EMS 2020 - Failure to Follow Basic Cyber Security Practices|MC EMS 2020 - Failure to Follow Basic Cyber Security Practices]] | |||
** [[The Anomalies#MC EMS 2020 - Anonymous Logins|MC EMS 2020 - Anonymous Logins]] | |||
** [[The Anomalies#MC EMS 2020 - Dual Boot System Discovered|MC EMS 2020 - Dual Boot System Discovered]] | |||
** [[The Anomalies#MC EMS 2020 - Operating System Logs Not Preserved|MC EMS 2020 - Operating System Logs Not Preserved]] | |||
** [[The Anomalies#MC EMS 2020 - Internet Connections to the EMS|MC EMS 2020 - Internet Connections to the EMS]] | |||
Latest revision as of 20:16, 27 August 2026
Control Activities
Principle 11 - Design General Control Activities over Information Technology
Attribute 11.07 - Management designs appropriate types of general control activities to mitigate information security risks. General control activities are the actions established through policies and procedures that apply to all or a large segment of an entity's information technology. They support the proper operation of the entity's information technology by creating a suitable environment for effective operation of application and user control activities. When designing general control activities, management evaluates information security objectives to meet the defined information requirements. General control activities are designed to achieve one or more of the following information security objectives:
- Confidentiality - Preserving authorized restrictions on information access and disclosure, including means for protecting privacy and sensitive information.
- Integrity - Guarding against improper information modification or destruction, which includes ensuring information's nonrepudiation and authenticity.
- Availability - Ensuring timely and reliable access to and use of information, thus preventing the disruption of access to or use of information or information technology.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - 11.06
- Next Attribute - 11.08
Jamie's Story
No examples are available to illustrate governance gaps for this attribute.
Election Anomalies
Arizona Senate Allegations
Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the Arizona Attorney General's Office 2020 General Election Investigation. This Green Book attribute applies given the Arizona Senate's concern that the 2020 election related to the integrity of the data.
- Maricopa Election Management Server (2020)
- MC EMS 2020 - Election Management System Database Purged
- MC EMS 2020 - Election Files Deleted
- MC EMS 2020 - Corrupt Ballot Images
- MC EMS 2020 - Missing Ballot Images
- MC EMS 2020 - Failure to Follow Basic Cyber Security Practices
- MC EMS 2020 - Anonymous Logins
- MC EMS 2020 - Dual Boot System Discovered
- MC EMS 2020 - Operating System Logs Not Preserved
- MC EMS 2020 - Internet Connections to the EMS
