Maricopa Election Management Server (2020): Difference between revisions

From Corrective Action Plan AZ
No edit summary
 
(13 intermediate revisions by the same user not shown)
Line 1: Line 1:
This page seeks to explain potential governance gaps with respect to allegations from the Arizona Senate, specifically for allegation #3 Maricopa County Election Department - Election Management System anomalies. These were investigated by the [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation] Report. This topic is listed on [[The Anomalies|'''Election Anomalies''']] page, which lists various election-related anomalies that illustrate poor governance.
In your exploration of election-related anomalies, you are here:


''Governance Gaps'' are reported on and compared to a standard so that you may visualize how poorly managed County services can have an adverse impact without any criminal wrongdoing. We chose the United States Government Accountability Office's (GAO) ''Standards for Internal Control in the Federal Government'' (also known as the ''Green Book'') because it represents the ideal standard for governance practices since it is specifically written for government entities, not the business sector. Maricopa County has no obligation or commitments to adhere to any governance-related standards, including the Green Book. Regardless, the Green Book is a representation of what good governance looks like and deviations from that standard are worthy of consideration, not prosecution.
* List of [[The Anomalies|Election Anomalies]]
The Governance Gap Assessment Team are not IT security experts. The technical aspects of the IT configuration are not being disputed. The assessment for governance gaps sought to understand how data and information was being treated with respect to the US GAO's [https://www.gao.gov/assets/gao-25-107721.pdf Standards for Internal Control in the Federal Government.]
** [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Inspector's report of Arizona Senate of Allegations]
*** Allegation '''#3: Maricopa County Election Department - Election Management System'''--
**** --[Click for [[Dropbox Collection (2020)|Allegation #2]] or [[Maricopa County Board of Supervisors Withholding Audit Data (2020)|Allegation #4]]]
=== List of Election Management System Sub-allegations ===
This section lists the Sub-allegations from Allegation #3 as submitted by the Arizona Senate on September 24, 2021 to the Arizona Attorney General for investigation.  


=== List of Allegations ===
Each sub-allegation was assessed independently for governance gaps. Click on each of the Sub-allegations to learn more about those governance gaps.  
[[MC EMS 2020 - Election Management System Database Purged|The]] following allegations were submitted by the Arizona Senate in 2021 to the Arizona Attorney General for investigation. These were investigated as allegation #3 in the AZ AG's inspector report. Each sub-allegation was assessed independently for governance gaps, which are explained on separate web pages.
# [[MC EMS 2020 - Election Management System Database Purged|Election Management System Database Purged]]
# [[MC EMS 2020 - Election Management System Database Purged|Election Management System Database Purged]]
# Election Files Deleted
# [[MC EMS 2020 - Election Files Deleted|Election Files Deleted]]
# Corrupt Ballot Images
# [[MC EMS 2020 - Corrupt Ballot Images|Corrupt Ballot Images]]
# Missing Ballot Images
# [[MC EMS 2020 - Missing Ballot Images|Missing Ballot Images]]
# Failure to Follow Basic Cyber Security Practices
# [[MC EMS 2020 - Failure to Follow Basic Cyber Security Practices|Failure to Follow Basic Cyber Security Practices]]
# Subpoenaed Equipment Not Yet Provided
# [[MC EMS 2020 - Subpoenaed Equipment Not Yet Provided|Subpoenaed Equipment Not Yet Provided]]
# Anonymous Logins
# [[MC EMS 2020 - Anonymous Logins|Anonymous Logins]]
# Dual Boot System Discovered
# [[MC EMS 2020 - Dual Boot System Discovered|Dual Boot System Discovered]]
# Operating System Logs Not Preserved
# [[MC EMS 2020 - Operating System Logs Not Preserved|Operating System Logs Not Preserved]]
# Internet Connections to the EMS
# [[MC EMS 2020 - Internet Connections to the EMS|Internet Connections to the EMS]]
 
==== 1 - Election Management System Database Purged ====
<u>Allegation</u>
 
The Elections Management System (EMS) database was allegedly purged of all the details associated with the 2020 General Election. The allegation originated from Cyber Ninjas. They explain that all election results were cleared by a Results Talley and Reporting Admin on 2/2/21 at 1714, which was the "evening before" the Pro V & V Audit was scheduled to officially start.
 
<u>Relevant Inspector Notes</u>
 
The AZ AG's inspector reports the following statement from the MC Director of Information Technology, Nate Young, "the server database was required to be clean for the logic and accuracy tests completed by Pro V&V and SLI Compliance on February 1, 2021.
 
<u>Inspector's Finding</u>
 
'''Indeterminate.''' Agents are pending a date to review archived data to ensure all elections files are present.
 
<u>Governance Gap Assessment:</u>
 
* As of the winter of 2021, all of the election files were still not available for inspection by the AZ AG's inspectors, after more than one year had elapsed since the General Election of 2121.
* The report states follow up is needed but does not identify any one person accountable for the follow up. This issue remains unresolved based on the contents.
 
==== 2 - Election Files Deleted ====
<u>Allegation</u>
 
The Master File Table (MFT) of the drives, and a large number of files on the Election Management System (EMS) Server, and on the HiPro Scanner machines were allegedly deleted. This allegation originated with Cyber Ninjas. The deleted files included ballot images, election related databases, results files, and log files.
 
<u>Relevant Inspector Notes</u>
 
* Central count tabulation stations are comprised of a computer and scanner.
* Data files are shared/transferred over the local network to the EMS server. 
* Data files are removed from the tabulation stations when data space (memory) on the computer begins to get full.
* Since these files are not associated to the tabulation files stored on the EMS server, they are not backed-up or archived.
* February 2, 2021 - Standard archive steps were taken for the EMS server and Tabulation Stations were prepared for a March 2021 election.
* February 2 -12, 2021 - Pro V&V and SLI conducted audits on election equipment.
* February 11, 2021 - Election staff prepared the EMS server and other for a scheduled audit certification.
* March 3, 2021 - Election staff gathered subpoenaed ballot images from archive.
* April 12, 2021 - Election staff prepared EMS server and other election equipment for subpoena delivery.
 
<u>Inspector's Finding</u>
 
'''Indeterminate -''' Agents are pending a date to review archived data to ensure all election files are present.
 
<u>Governance Gaps Assessment</u>
 
* As of the winter of 2021, all of the election files were still not available for inspection by the AZ AG's inspectors, after more than one year had elapsed since the General Election of 2121.
* The report states follow up is needed but does not identify any one person accountable for the follow up. This issue remains unresolved based on the contents.
* The AZ AG's inspector description of files lacked specificity. It's difficult to understand the consequences to sensitive files when terms like "data files" and "these files" are being used without knowing how they related to vote tabulation.
 
==== 3 - Corrupt Ballot Images ====
<u>Allegation</u>
 
The was an allegation of 263,139 unreadable ballot images. This allegation originated with Cyber Ninjas.
 
<u>Relevant Inspector Notes</u>
 
The AZ AG's inspector was told, MC Election officials randomly selected images during January 2022 from the date period of allegedly corrupted ballots and were able to open all images.
 
<u>Inspector's Finding</u>
 
'''Undetermined.''' Agents are pending a date to review archived data to ensure all election files are present.
 
<u>Governance Gaps Assessment</u>
 
* As of the winter of 2021, all of the election files were still not available for inspection by the AZ AG's inspectors, after more than one year had elapsed since the General Election of 2121.
* The report states follow up is needed but does not identify any one person accountable for the follow up. This issue remains unresolved based on the contents.
* Sometimes words matter. The allegation was 263,139 ballots were ''<u>unreadable</u>''. MC randomly ''<u>opened</u>'' selected images. Agents were unable to determine if the files were ''<u>present.</u>'' Given that specific value of 263,139, it's not clear why those ballots were not made available to the inspectors to determine if they were readable.
 
==== 4 - Missing Ballot Images ====
<u>Allegation</u>
 
The total amount of ballot images is allegedly less than the official vote count. The allegation originated from Cyber Ninjas.
 
<u>Relevant Inspector Notes</u>
 
* "During the investigation, agents leaned that Maricopa County Election Officials during the Correcting the Record report in January 2022, reviewed the cloned copies of hard drives that were provided to Cyber Ninjas and located the files that were claimed missing."
 
<u>Inspector's Finding</u>
 
'''Undetermined.''' Agents are pending a date to review archived data to ensure all election files are present.
 
<u>Governance Gaps Assessment</u>
 
* As of the winter of 2021, all of the election files were still not available for inspection by the AZ AG's inspectors, after more than one year had elapsed since the General Election of 2121.
* The report states follow up is needed but does not identify any one person accountable for the follow up. This issue remains unresolved based on the contents.
* The AZ AG's inspector's note begs a follow up question. It MC said they found the records, why were the agents able to close this issue as being unfounded.
 
==== 5 - Failure to Follow Basic Cyber Security Practices ====
<u>Allegation</u>
 
The Basic Cyber Security Practices were allegedly not followed. The allegation originated from Cyber Ninjas. They explained the Department of Homeland Security's Cybersecurity & Infrastructure Security Agency (CISA) has guidelines, which MC was not following.
 
<u>Relevant Inspector Notes</u>
 
* The EMS server along other election equipment is configured in an air gapped standalone system (no outside connectivity outside of the control access room).
* CISA guidelines are not applicable because of the air gapped configuration.
* The EMS server along with the other election equipment resides inside a controlled access room under 24-hour video monitoring.
* A two-person rule is required to enter the room.
 
<u>Inspector's Finding</u>
 
Unfounded Allegation. The inspector found no indication of malicious or criminal acts performed by Maricopa County Elections Officials.
 
<u>Governance Gaps Assessment</u>
 
* The AZ AG's inspector explains the equipment is under 24-hour surveillance. However, the inspector did not claim to have reviewed the surveillance videos. In fact, the surveillance videos were likely unavailable given the common practice to overwrite the video data with new surveillance video data after a sufficient time has elapsed to retrieve video data from the suspected time frame. Without an independent review of the surveillance video by the inspector, there seems to be an overreliance on the simple existence of the 24-hour camera to make the assertion of "no malicious or criminal acts.
* The AZ AG's inspector relied on the MC leadership team claiming that a two-person rule is required to enter the room. There is no indication that the 24-hour video data was reviewed to confirm the two-person rule was always applied.
* The AZ AG's inspector did not report on the existence of an entry and exit log for each person, which was maintained by a third independent person uninvolved with the EMS activities.
* The AZ AG's inspector had already noted that procedure violations had occurred during drop box collections. It would have seemed critical for the inspector to claim "no indication of malicious or criminal acts" if objective data was not reviewed to confirm compliance with the two-person rule.
* The AZ AG's inspector was told of a two-person rule. During the inspector's investigation of the drop box collection allegations, the two-person rule was more specific. One member of each political party (i.e., Democrat and Republican) had to be assigned to a collection team. The consequence of malicious and criminal performed on the EMS would be far more serious than a drop box collection, but the teaming requirement is less restrictive. In this case, the two-person rule is being questioned as being too lenient for the associated risk.
* The AZ AG's inspector was told the Maricopa County within compliance of state and federal law as it pertains to these areas. Federal laws and Arizona Statutes are essentially policy statements, which affected entities are obligated to follow. Laws and statutes do not typically provide the necessary details form implementation of the laws and statutes. The inspector did not identify any IT standards for data security that MC Elections were following. They only claim to be in compliance with laws and statutes without any standard.
 
==== 6 - Subpoenaed Equipment Not Yet Provided ====
<u>Allegation</u>
 
Cyber Ninjas alleges the Maricopa County Recorder's Office did not provide all of the equipment requested under the subpoena.
 
<u>Relevant Inspector Notes</u>
 
"During an interview with Mr. Gates from the Maricopa County Board of Supervisors, all data and equipment was provided as requested by the subpoena and that items not subpoenaed were not provided to the State Senate. He further related that sensitive routers and log files were not provided and were part of the settlement agreement. Mr. Gates stated he is not aware of what was provided to Cyber Ninjas by the Senate and that question should be directed to Senate President Fann."
 
<u>Inspector's Finding</u>
 
Unfounded Allegation. According to statements made by Mr. Bill Gates and a letter dated September 17, 2021 by State Senate President Karen Fann to Attorney General Mark Brnovich, all materials were provided to the State Senate by Maricopa County.
 
<u>Governance Gaps Assessment</u>
 
* It's interesting to note that the allegation was against the Maricopa County Recorder's Office (MCRO). However, the AZ AG's inspector directed his questions to the Chairman of the Maricopa County Board of Supervisors (MCBOS). The MCRO does not report to the MCBOS.
* The equipment was not voluntarily released to the Arizona State Senate, which was in an oversight role. Apparently, the issue was litigated, and the scope of equipment was agreed upon in a court settlement.
* The AZ AG's inspector reports that the Chairman of the MCBOS is withholding sensitive routers and log files as part of the settlement agreement.
 
==== 7 - Anonymous Logins ====
<u>Allegation</u>
 
Anonymous logins allegedly occurred. The allegation originated from Cyber Ninjas.
 
The AZ AG's inspector notes, "Cyber Ninjas stated there are common functions in Windows which will record login activity to security logs. Logins exhibit known recording sequences within the logs that allow analysis to determine the origination of the requesting function and determine the legitimacy of the logged action."
 
Paraphrased by the Governance Gap Assessment team: Cyber Ninjas appears to have observed a record of actions being taken within a Window-based computer. However, they were unable to determine who was performing the functions. The concern appears to be with the anonymity of the log in, not the actual changes made by the person with the anonymous login.
 
<u>Relevant Inspector Notes</u>
 
"Within the PacketWatch report, there was a section identified specific to these allegations. Per PacketWatch they reviewed logs from 11/18/2020 - 3/5/2021. During that time frame, they observed 205 Logon Type 3 evens and 5 of them had "anonymous logon" as the account name. PacketWatch indicated they further reviewed the logons and indicated they are normal interactions between Windows-based devices that are connected on the same network where one or more of them have resources shared (shared drives, printers, etc.) to the network. Packet Watch further stated there were no logged events in the proximity of these events to indicate the "anonymous" user was running any "script-based activity."
 
<u>Inspector's Finding</u>
 
'''Undetermined''' - The allegations by Cyber Ninjas appear to have different activity dates as to that which was reviewed by PacketWatch. Agents have a pending request to review anonymous logins with Election Officials.
 
<u>Governance Gaps Assessment</u>
 
* As of the winter of 2021, all of the election files were still not available for inspection by the AZ AG's inspectors, after more than one year had elapsed since the General Election of 2121.
* The report states follow up is needed but does not identify any one person accountable for the follow up. This issue remains unresolved based on the contents.
* It's unclear why the AZ AG's inspector spent time using a prior report by PacketWatch. The PacketWatch report addressed a different time frame than the Cyber Ninjas allegations. Therefore, the PacketWatch report was irrelevant from the perspective of addressing the allegations.
* That said, the AZ AG's use of the PacketWatch report seemed to support Cyber Ninjas allegations. The detection of anonymous logins in different time frames by separate entity (i.e.,  PacketWatch) than reported by Cyber Ninjas would confirm anonymous logons.
* There is the possibility that script-based activities had been run by an anonymous logon during Cyber Ninjas time frame given those events were not reviewed by the inspector.
* MC staff was apparently silent on the issue. The PacketWatch report was already completed and available for review by the AZ AG's inspector. However, there inspector did not note that the County had taken any investigative or corrective actions to address anonymous logons.
 
==== 8 - Dual Boot System Discovered ====
<u>Allegation</u>
 
 
<u>Relevant Inspector Notes</u>
 
 
<u>Inspector's Finding</u>
 
 
<u>Governance Gaps Assessment</u>
 
x
 
==== 9 - Operating System Logs Not Preserved ====
<u>Allegation</u>
 
 
<u>Relevant Inspector Notes</u>
 
 
<u>Inspector's Finding</u>
 
 
<u>Governance Gaps Assessment</u>
 
x
 
==== 10 - Internet Connections to the EMS ====
<u>Allegation</u>
 
 
<u>Relevant Inspector Notes</u>
 
 
<u>Inspector's Finding</u>
 
 
<u>Governance Gaps Assessment</u>
 
x

Latest revision as of 18:30, 1 September 2026

In your exploration of election-related anomalies, you are here:

List of Election Management System Sub-allegations

This section lists the Sub-allegations from Allegation #3 as submitted by the Arizona Senate on September 24, 2021 to the Arizona Attorney General for investigation.

Each sub-allegation was assessed independently for governance gaps. Click on each of the Sub-allegations to learn more about those governance gaps.

  1. Election Management System Database Purged
  2. Election Files Deleted
  3. Corrupt Ballot Images
  4. Missing Ballot Images
  5. Failure to Follow Basic Cyber Security Practices
  6. Subpoenaed Equipment Not Yet Provided
  7. Anonymous Logins
  8. Dual Boot System Discovered
  9. Operating System Logs Not Preserved
  10. Internet Connections to the EMS