8.04: Difference between revisions
No edit summary |
|||
| (6 intermediate revisions by the same user not shown) | |||
| Line 4: | Line 4: | ||
'''Attribute 8,04''' - Management considers the types of fraud, improper payments, and information security breaches that may occur, along with relevant risk factors, when identifying risks related to these areas. While risks may be greater when multiple risk factors are present, the presence of one factor may still indicate a risk. Performing an analysis to identify the root cause of identified internal control deficiencies can assist management in identifying risks. | '''Attribute 8,04''' - Management considers the types of fraud, improper payments, and information security breaches that may occur, along with relevant risk factors, when identifying risks related to these areas. While risks may be greater when multiple risk factors are present, the presence of one factor may still indicate a risk. Performing an analysis to identify the root cause of identified internal control deficiencies can assist management in identifying risks. | ||
__FORCETOC__ | |||
=== [[March 12, 2026: | '''Navigational Buttons:''' | ||
The discussion of Attribute 8.04 is from this March 12, 2026 event, under the subheading of Motor Vehicle Department Contract | * '''[[Index of Attributes]]''' | ||
* '''Previous Attribute - [[8.03]]''' | |||
* '''Next Attribute - [[8.05]]'''__FORCETOC__ | |||
=== Jamie's Story === | |||
==== [[March 12, 2026: Maricopa County Defense Briefing]] ==== | |||
The discussion of Attribute 8.04 is from this March 12, 2026 event, under the subheading of Motor Vehicle Department Contract. | |||
This Green Book attribute is fundamentally saying that a single risk factor can be more significant that a list of other risk. The likelihood and consequences from a single risk factor can be significant. This attribute describes how root cause analysis to address internal control deficiencies is good governance. Root cause analysis identifies the organizational risk and Corrective Action Plans mitigate that risk. Contrary to the Green Book, MC did not provide me with any objective evidence that demonstrated their interest in investigating election-related anomalies for the purpose of understanding the risk to election outcomes and developing corrective actions where necessary. | |||
=== Election Anomalies === | |||
The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment. | |||
The Green Book's <u>emphasis on fraud and information security</u> as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security. | |||
===== [[Dropbox Collection (2020)|Maricopa Dropbox Collection (2020)]] ===== | |||
Governance issues identified from [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation] of Arizona Senate allegations of Maricopa County Election Department - Drop Box Collections issues. Section 2 of the AZ AG's inspector's report identifies numerous issues, which present risk to potential fraud. | |||
This attribute states, ".While risks may be greater when multiple risk factors are present, the presence of one factor may still indicate a risk. Performing an analysis to identify the root cause of identified internal control deficiencies can assist management in identifying risks." | |||
The AZ AG's inspectors interview with the USPS inspector is interesting in that over 56,000 undelivered early ballots are discussed in a tone of minor process anomalies. Neither inspector considered the risk significance of these undelivered early ballots, which were still valid while under the control of the USPS. These valid ballots could have been used for fraudulent purposes if stolen from the USPS. Yet, the interview did not describe any additional precautions to protect these early ballots and implement a chain of custody until after the election, when they would have had no value to fraudsters. | |||
* See the heading [[Dropbox Collection (2020)#Deviation: Fictious Addresses in the MC Voter Registration Database|Deviation: Fictious Addresses in MC Voter Registration Database]] from Maricopa Dropbox Collection (2020) webpage. | |||
* See the heading [[Dropbox Collection (2020)#Noteworthy: Transmission of USPS Data to MC and Runbeck|Noteworthy: Transmission of USPS Data to MC and Runbeck]] from Maricopa Dropbox Collection (2020) webpage | |||
===== [[Signature Verification|Maricopa County Signature Verification (2020)]] ===== | |||
Governance issues identified from [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation] of Arizona Senate allegations of Maricopa County - Signature Verification Process issues. As this attribute, one factor may, and in this case, does present risk. The one factor is the one person that makes fraud decisions every seven-seconds. No root cause has been performed as this attribute suggests. | |||
Latest revision as of 10:37, 14 September 2026
Risk Assessment
Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk
Attribute 8,04 - Management considers the types of fraud, improper payments, and information security breaches that may occur, along with relevant risk factors, when identifying risks related to these areas. While risks may be greater when multiple risk factors are present, the presence of one factor may still indicate a risk. Performing an analysis to identify the root cause of identified internal control deficiencies can assist management in identifying risks.
Navigational Buttons:
- Index of Attributes
- Previous Attribute - 8.03
- Next Attribute - 8.05
Jamie's Story
The discussion of Attribute 8.04 is from this March 12, 2026 event, under the subheading of Motor Vehicle Department Contract.
This Green Book attribute is fundamentally saying that a single risk factor can be more significant that a list of other risk. The likelihood and consequences from a single risk factor can be significant. This attribute describes how root cause analysis to address internal control deficiencies is good governance. Root cause analysis identifies the organizational risk and Corrective Action Plans mitigate that risk. Contrary to the Green Book, MC did not provide me with any objective evidence that demonstrated their interest in investigating election-related anomalies for the purpose of understanding the risk to election outcomes and developing corrective actions where necessary.
Election Anomalies
The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.
The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.
Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County Election Department - Drop Box Collections issues. Section 2 of the AZ AG's inspector's report identifies numerous issues, which present risk to potential fraud.
This attribute states, ".While risks may be greater when multiple risk factors are present, the presence of one factor may still indicate a risk. Performing an analysis to identify the root cause of identified internal control deficiencies can assist management in identifying risks."
The AZ AG's inspectors interview with the USPS inspector is interesting in that over 56,000 undelivered early ballots are discussed in a tone of minor process anomalies. Neither inspector considered the risk significance of these undelivered early ballots, which were still valid while under the control of the USPS. These valid ballots could have been used for fraudulent purposes if stolen from the USPS. Yet, the interview did not describe any additional precautions to protect these early ballots and implement a chain of custody until after the election, when they would have had no value to fraudsters.
- See the heading Deviation: Fictious Addresses in MC Voter Registration Database from Maricopa Dropbox Collection (2020) webpage.
- See the heading Noteworthy: Transmission of USPS Data to MC and Runbeck from Maricopa Dropbox Collection (2020) webpage
Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County - Signature Verification Process issues. As this attribute, one factor may, and in this case, does present risk. The one factor is the one person that makes fraud decisions every seven-seconds. No root cause has been performed as this attribute suggests.
