8.15: Difference between revisions
No edit summary |
|||
| (2 intermediate revisions by the same user not shown) | |||
| Line 14: | Line 14: | ||
No examples are available to illustrate governance gaps for this attribute. | No examples are available to illustrate governance gaps for this attribute. | ||
== Election Anomalies == | === Election Anomalies === | ||
The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment. | |||
The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security. | |||
===== Arizona Senate Allegations ===== | |||
Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the Arizona Attorney General's Office 2020 General Election Investigation. These allegations were associated with Information Technology (IT) used to tabulate election results. Maricopa County and Dominion employees were primarily responsible for this equipment. However, the Arizona Senate's allegations were exclusively directed towards MC IT services. This Green Book attribute applies given the Arizona Senate's concern was that some of the 2020 election fraud potential may have occurred internally, within the scope of MC's IT services. | |||
* [[The Anomalies#Maricopa Election Management Server (2020)|Maricopa Election Management Server (2020)]] | |||
** [[The Anomalies#MC EMS 2020 - Election Management System Database Purged|MC EMS 2020 - Election Management System Database Purged]] | |||
** [[The Anomalies#MC EMS 2020 - Election Files Deleted|MC EMS 2020 - Election Files Deleted]] | |||
** [[The Anomalies#MC EMS 2020 - Corrupt Ballot Images|MC EMS 2020 - Corrupt Ballot Images]] | |||
** [[The Anomalies#MC EMS 2020 - Missing Ballot Images|MC EMS 2020 - Missing Ballot Images]] | |||
** [[The Anomalies#MC EMS 2020 - Failure to Follow Basic Cyber Security Practices|MC EMS 2020 - Failure to Follow Basic Cyber Security Practices]] | |||
** [[The Anomalies#MC EMS 2020 - Subpoenaed Equipment Not Yet Provided|MC EMS 2020 - Subpoenaed Equipment Not Yet Provided]] | |||
** [[The Anomalies#MC EMS 2020 - Anonymous Logins|MC EMS 2020 - Anonymous Logins]] | |||
** [[The Anomalies#MC EMS 2020 - Dual Boot System Discovered|MC EMS 2020 - Dual Boot System Discovered]] | |||
** [[The Anomalies#MC EMS 2020 - Operating System Logs Not Preserved|MC EMS 2020 - Operating System Logs Not Preserved]] | |||
** [[The Anomalies#MC EMS 2020 - Internet Connections to the EMS|MC EMS 2020 - Internet Connections to the EMS]] | |||
===== [[Signature Verification|Maricopa County Signature Verification (2020)]] ===== | |||
Note: This attribute does not appear to apply, because the procedure non-compliance issues appear to be intentional, not unintentional, given the quantity of violations that occurred. This is a clarifying comment for governance issues identified from [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation] of Arizona Senate allegations of Maricopa County - Signature Verification Process issues. This was not identified as a governance gap. | |||
Latest revision as of 15:56, 27 August 2026
Risk Assessment
Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk
Attribute 8.15 - Internal risks include unintentional acts by employees, whose vigilance is a key defense against external threats and user error. Internal threats may also come from intentional malicious acts by former or disgruntled employees. They pose unique risks because these individuals may be both motivated to work against the entity and better equipped to succeed in carrying out a malicious act as they have greater access to and knowledge of the entity's information technology and business processes.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - 8.14
- Next Attribute - 8.16
Jamie's Story
No examples are available to illustrate governance gaps for this attribute.
Election Anomalies
The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.
The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.
Arizona Senate Allegations
Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the Arizona Attorney General's Office 2020 General Election Investigation. These allegations were associated with Information Technology (IT) used to tabulate election results. Maricopa County and Dominion employees were primarily responsible for this equipment. However, the Arizona Senate's allegations were exclusively directed towards MC IT services. This Green Book attribute applies given the Arizona Senate's concern was that some of the 2020 election fraud potential may have occurred internally, within the scope of MC's IT services.
- Maricopa Election Management Server (2020)
- MC EMS 2020 - Election Management System Database Purged
- MC EMS 2020 - Election Files Deleted
- MC EMS 2020 - Corrupt Ballot Images
- MC EMS 2020 - Missing Ballot Images
- MC EMS 2020 - Failure to Follow Basic Cyber Security Practices
- MC EMS 2020 - Subpoenaed Equipment Not Yet Provided
- MC EMS 2020 - Anonymous Logins
- MC EMS 2020 - Dual Boot System Discovered
- MC EMS 2020 - Operating System Logs Not Preserved
- MC EMS 2020 - Internet Connections to the EMS
Note: This attribute does not appear to apply, because the procedure non-compliance issues appear to be intentional, not unintentional, given the quantity of violations that occurred. This is a clarifying comment for governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County - Signature Verification Process issues. This was not identified as a governance gap.
