MC EMS 2020 - Anonymous Logins: Difference between revisions

From Corrective Action Plan AZ
No edit summary
 
(2 intermediate revisions by the same user not shown)
Line 1: Line 1:
In your exploration of election-related anomalies, you are here:
* List of [[The Anomalies|Election Anomalies]]
** [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Inspector's report of Arizona Senate of Allegations]
*** Allegation [[Maricopa Election Management Server (2020)|#3: Maricopa County Election Department - Election Management System]]----[Click for [[Dropbox Collection (2020)|Allegation #2]] or Allegation #4]
**** Sub-allegation '''#7 - Anonymous Logins''' ---- [Click for [[MC EMS 2020 - Subpoenaed Equipment Not Yet Provided|Sub-allegation #6]] or [[MC EMS 2020 - Dual Boot System Discovered|Sub-allegation #8]]]
This page seeks to explain potential governance gaps with respect to allegations from the Arizona Senate, specifically for allegation #3 Maricopa County Election Department - Election Management System anomalies. These were investigated by the Arizona Attorney General's Office 2020 General Election Investigation Report. This topic is listed on [[The Anomalies|'''Election Anomalies''']] page, which lists various election-related anomalies that illustrate poor governance.
This page seeks to explain potential governance gaps with respect to allegations from the Arizona Senate, specifically for allegation #3 Maricopa County Election Department - Election Management System anomalies. These were investigated by the Arizona Attorney General's Office 2020 General Election Investigation Report. This topic is listed on [[The Anomalies|'''Election Anomalies''']] page, which lists various election-related anomalies that illustrate poor governance.


Line 10: Line 17:
Governance gaps were identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations #3 Maricopa County Election Department - Election Management Server (EMS) issues, which consisted of ten separate allegations. MC EMS 2020 - Election Management System Database Purged is an assessment of one of the ten sub-allegations associated with the EMS.
Governance gaps were identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations #3 Maricopa County Election Department - Election Management Server (EMS) issues, which consisted of ten separate allegations. MC EMS 2020 - Election Management System Database Purged is an assessment of one of the ten sub-allegations associated with the EMS.


=== Allegation ===
===== Allegation =====
Anonymous logins allegedly occurred. The allegation originated from Cyber Ninjas.
 
The AZ AG's inspector notes, "Cyber Ninjas stated there are common functions in Windows which will record login activity to security logs. Logins exhibit known recording sequences within the logs that allow analysis to determine the origination of the requesting function and determine the legitimacy of the logged action."
 
Paraphrased by the Governance Gap Assessment team: Cyber Ninjas appears to have observed a record of actions being taken within a Window-based computer. However, they were unable to determine who was performing the functions. The concern appears to be with the anonymity of the log in, not the actual changes made by the person with the anonymous login.
 
===== <u>Relevant Inspector Notes</u> =====
"Within the PacketWatch report, there was a section identified specific to these allegations. Per PacketWatch they reviewed logs from 11/18/2020 - 3/5/2021. During that time frame, they observed 205 Logon Type 3 evens and 5 of them had "anonymous logon" as the account name. PacketWatch indicated they further reviewed the logons and indicated they are normal interactions between Windows-based devices that are connected on the same network where one or more of them have resources shared (shared drives, printers, etc.) to the network. Packet Watch further stated there were no logged events in the proximity of these events to indicate the "anonymous" user was running any "script-based activity."
 
===== <u>Inspector's Finding</u> =====
'''Undetermined''' - The allegations by Cyber Ninjas appear to have different activity dates as to that which was reviewed by PacketWatch. Agents have a pending request to review anonymous logins with Election Officials.
 
===== <u>Governance Gaps Assessment</u> =====
 
* As of the winter of 2021, all of the election files were still not available for inspection by the AZ AG's inspectors, after more than one year had elapsed since the General Election of 2121.
* The report states follow up is needed but does not identify any one person accountable for the follow up. This issue remains unresolved based on the contents.
* It's unclear why the AZ AG's inspector spent time using a prior report by PacketWatch. The PacketWatch report addressed a different time frame than the Cyber Ninjas allegations. Therefore, the PacketWatch report was irrelevant from the perspective of addressing the allegations.
* That said, the AZ AG's use of the PacketWatch report seemed to support Cyber Ninjas allegations. The detection of anonymous logins in different time frames by separate entity (i.e.,  PacketWatch) than reported by Cyber Ninjas would confirm anonymous logons.
* There is the possibility that script-based activities had been run by an anonymous logon during Cyber Ninjas time frame given those events were not reviewed by the inspector.
* MC staff was apparently silent on the issue. The PacketWatch report was already completed and available for review by the AZ AG's inspector. However, there inspector did not note that the County had taken any investigative or corrective actions to address anonymous logons.


=== Potential Governance Gap(s): ===
=== Potential Governance Gap(s): ===


* Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
* Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
** Attribute(s):
** Attribute(s): [[1.01]], [[1.02]], [[1.04]], [[1.05]], [[1.08]]
* Principle 2 - Exercise Oversight Responsibility
* Principle 2 - Exercise Oversight Responsibility
** Attribute(s):
** Attribute(s): [[2.01]]
* Principle 3 - Establish Structure, Responsibility, and Authority
* Principle 3 - Establish Structure, Responsibility, and Authority
** Attribute(s):
** Attribute(s): [[3.09]], [[3.10]]
* Principle 4 - Demonstrate Commitment to Competence
* Principle 4 - Demonstrate Commitment to Competence
** Attribute(s):
** Attribute(s): [[4.03]]
* Principle 5 - Enforce Accountability
* Principle 5 - Enforce Accountability
** Attribute(s):
** Attribute(s):
* Principle 6 - Define Objectives and Risk Tolerances
* Principle 6 - Define Objectives and Risk Tolerances
** Attribute(s):
** Attribute(s): [[6.05]]
* Principle 7 - Identify, Analyze, and Respond to Risks
* Principle 7 - Identify, Analyze, and Respond to Risks
** Attribute(s):
** Attribute(s): [[7.05]], [[7.06]], [[7.09]], [[7.15]]
* Principle 8 - Assess Fraud, Improper Payment, and Information
* Principle 8 - Assess Fraud, Improper Payment, and Information
** Attribute(s):
** Attribute(s): [[8.01]], [[8.02]], [[8.03]], [[8.04]], [[8.05]], [[8.06]], [[8.10]], [[8.14]], [[8.15]], [[8.16]]
* Principle 9 - Identify, Analyze, and Respond to Change
* Principle 9 - Identify, Analyze, and Respond to Change
** Attribute(s):
** Attribute(s):
* Principle 10 - Design Control Activities
* Principle 10 - Design Control Activities
** Attribute(s):
** Attribute(s): [[10.01]], [[10.18]], [[10.19]]
* Principle 11 - Design General Control Activities over Information
* Principle 11 - Design General Control Activities over Information
** Attribute(s):
** Attribute(s): [[11.02]], [[11.07]], [[11.09]], [[11.10]], [[11.11]]
* Principle 12 - Implement Control Activities
* Principle 12 - Implement Control Activities
** Attribute(s):
** Attribute(s): [[12.01]], [[12.02]], [[12.03]]
* Principle 13 - Use Quality Information
* Principle 13 - Use Quality Information
** Attribute(s):
** Attribute(s):
Line 43: Line 70:
** Attribute(s):
** Attribute(s):
* Principle 15 - Communicate Externally
* Principle 15 - Communicate Externally
** Attribute(s):
** Attribute(s): [[15.02]], [[15.09]]
* Principle 16 - Perform Monitoring Activities
* Principle 16 - Perform Monitoring Activities
** Attribute(s):
** Attribute(s): [[16.09]], [[16.10]]
* Principle 17 - Evaluate Issues and Remediate Deficiencies
* Principle 17 - Evaluate Issues and Remediate Deficiencies
** Attribute(s):
** Attribute(s): [[17.01]], [[17.02]], [[17.03]], [[17.04]], [[17.05]], [[17.06]], [[17.08]]

Latest revision as of 15:29, 31 August 2026

In your exploration of election-related anomalies, you are here:

This page seeks to explain potential governance gaps with respect to allegations from the Arizona Senate, specifically for allegation #3 Maricopa County Election Department - Election Management System anomalies. These were investigated by the Arizona Attorney General's Office 2020 General Election Investigation Report. This topic is listed on Election Anomalies page, which lists various election-related anomalies that illustrate poor governance.

Governance Gaps are reported on and compared to a standard so that you may visualize how poorly managed County services can have an adverse impact without any criminal wrongdoing. We chose the United States Government Accountability Office's (GAO) Standards for Internal Control in the Federal Government (also known as the Green Book) because it represents the ideal standard for governance practices since it is specifically written for government entities, not the business sector. Maricopa County has no obligation or commitments to adhere to any governance-related standards, including the Green Book. Regardless, the Green Book is a representation of what good governance looks like and deviations from that standard are worthy of consideration, not prosecution.

The Governance Gap Assessment Team are not IT security experts. The technical aspects of the IT configuration are not being disputed. The assessment for governance gaps sought to understand how data and information was being treated with respect to the US GAO's Standards for Internal Control in the Federal Government.

Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County Election Department - Election Management Server (EMS) issues.

MC EMS 2020 - Anonymous Logins

Governance gaps were identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations #3 Maricopa County Election Department - Election Management Server (EMS) issues, which consisted of ten separate allegations. MC EMS 2020 - Election Management System Database Purged is an assessment of one of the ten sub-allegations associated with the EMS.

Allegation

Anonymous logins allegedly occurred. The allegation originated from Cyber Ninjas.

The AZ AG's inspector notes, "Cyber Ninjas stated there are common functions in Windows which will record login activity to security logs. Logins exhibit known recording sequences within the logs that allow analysis to determine the origination of the requesting function and determine the legitimacy of the logged action."

Paraphrased by the Governance Gap Assessment team: Cyber Ninjas appears to have observed a record of actions being taken within a Window-based computer. However, they were unable to determine who was performing the functions. The concern appears to be with the anonymity of the log in, not the actual changes made by the person with the anonymous login.

Relevant Inspector Notes

"Within the PacketWatch report, there was a section identified specific to these allegations. Per PacketWatch they reviewed logs from 11/18/2020 - 3/5/2021. During that time frame, they observed 205 Logon Type 3 evens and 5 of them had "anonymous logon" as the account name. PacketWatch indicated they further reviewed the logons and indicated they are normal interactions between Windows-based devices that are connected on the same network where one or more of them have resources shared (shared drives, printers, etc.) to the network. Packet Watch further stated there were no logged events in the proximity of these events to indicate the "anonymous" user was running any "script-based activity."

Inspector's Finding

Undetermined - The allegations by Cyber Ninjas appear to have different activity dates as to that which was reviewed by PacketWatch. Agents have a pending request to review anonymous logins with Election Officials.

Governance Gaps Assessment
  • As of the winter of 2021, all of the election files were still not available for inspection by the AZ AG's inspectors, after more than one year had elapsed since the General Election of 2121.
  • The report states follow up is needed but does not identify any one person accountable for the follow up. This issue remains unresolved based on the contents.
  • It's unclear why the AZ AG's inspector spent time using a prior report by PacketWatch. The PacketWatch report addressed a different time frame than the Cyber Ninjas allegations. Therefore, the PacketWatch report was irrelevant from the perspective of addressing the allegations.
  • That said, the AZ AG's use of the PacketWatch report seemed to support Cyber Ninjas allegations. The detection of anonymous logins in different time frames by separate entity (i.e., PacketWatch) than reported by Cyber Ninjas would confirm anonymous logons.
  • There is the possibility that script-based activities had been run by an anonymous logon during Cyber Ninjas time frame given those events were not reviewed by the inspector.
  • MC staff was apparently silent on the issue. The PacketWatch report was already completed and available for review by the AZ AG's inspector. However, there inspector did not note that the County had taken any investigative or corrective actions to address anonymous logons.

Potential Governance Gap(s):

  • Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
  • Principle 2 - Exercise Oversight Responsibility
  • Principle 3 - Establish Structure, Responsibility, and Authority
  • Principle 4 - Demonstrate Commitment to Competence
  • Principle 5 - Enforce Accountability
    • Attribute(s):
  • Principle 6 - Define Objectives and Risk Tolerances
  • Principle 7 - Identify, Analyze, and Respond to Risks
  • Principle 8 - Assess Fraud, Improper Payment, and Information
  • Principle 9 - Identify, Analyze, and Respond to Change
    • Attribute(s):
  • Principle 10 - Design Control Activities
  • Principle 11 - Design General Control Activities over Information
  • Principle 12 - Implement Control Activities
  • Principle 13 - Use Quality Information
    • Attribute(s):
  • Principle 14 - Communicate Internally
    • Attribute(s):
  • Principle 15 - Communicate Externally
  • Principle 16 - Perform Monitoring Activities
  • Principle 17 - Evaluate Issues and Remediate Deficiencies