8.14: Difference between revisions

From Arizona Citizen Voice
No edit summary
 
(5 intermediate revisions by the same user not shown)
Line 3: Line 3:
'''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk'''
'''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk'''


'''Attribute''' '''8.14''' - Management considers the types of risks that could impact the entity's information and information technology to provide a basis for identifying and analyzing risks related to information security.<sup>62</sup> Information security risk is the risk to entity operations, assets, and personnel, as well as external parties, due to unauthorized access, use, disclosure, disruption, modification, or destruction of information or information technology. These risks may impact the information security objectives of confidentiality, integrity, and availability.<sup>63</sup> Types of information security risk impacting each of these three objectives may include the following:
'''Attribute''' '''8.14''' - Management considers the types of risks that could impact the entity's information and information technology to provide a basis for identifying and analyzing risks related to information security. Information security risk is the risk to entity operations, assets, and personnel, as well as external parties, due to unauthorized access, use, disclosure, disruption, modification, or destruction of information or information technology. These risks may impact the information security objectives of confidentiality, integrity, and availability. Types of information security risk impacting each of these three objectives may include the following:


* '''Unauthorized access''' - End users, developers, or unrelated attackers may compromise the confidentiality of a platform or software system by overriding controls to gain unauthorized access to the entity's information technology or use capabilities that exceed their rights in those systems.
* '''Unauthorized access''' - End users, developers, or unrelated attackers may compromise the confidentiality of a platform or software system by overriding controls to gain unauthorized access to the entity's information technology or use capabilities that exceed their rights in those systems.
Line 14: Line 14:
'''>>>Navigational Buttons<<<'''
'''>>>Navigational Buttons<<<'''
* '''[[Index of Attributes]]'''
* '''[[Index of Attributes]]'''
* '''Previous Attribute - ?'''
* '''Previous Attribute - [[8.13]]'''
* '''Next Attribute - ?'''
* '''Next Attribute - [[8.15]]'''
__FORCETOC__
__FORCETOC__


=== '''No Examples''' ===
=== Jamie's Story ===
No examples are available to illustrate governance gaps for this attribute.
 
=== Election Anomalies ===
The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.
 
The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.
 
===== Arizona Senate Allegations =====
Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation]. This Green Book attribute applies given the Arizona Senate's concern that the 2020 election results may have been fraudulently reported, specifically for the following threats.
 
* '''Unauthorized access''' - End users, developers, or unrelated attackers may compromise the confidentiality of a platform or software system by overriding controls to gain unauthorized access to the entity's information technology or use capabilities that exceed their rights in those systems.
** [[The Anomalies#MC EMS 2020 - Subpoenaed Equipment Not Yet Provided|MC EMS 2020 - Subpoenaed Equipment Not Yet Provided]]
** [[The Anomalies#MC EMS 2020 - Anonymous Logins|MC EMS 2020 - Anonymous Logins]]
** [[The Anomalies#MC EMS 2020 - Dual Boot System Discovered|MC EMS 2020 - Dual Boot System Discovered]]
** [[The Anomalies#MC EMS 2020 - Internet Connections to the EMS|MC EMS 2020 - Internet Connections to the EMS]]
* '''Installation of malicious software''' - Installation of a program or file that intentionally attacks the entity's information technology by corrupting or stealing data, overwhelming a system with traffic, or locking the entity out. The objective of a malicious software (malware) attack may be to harm the entity, gain information, or obtain a financial gain.
** [[The Anomalies#MC EMS 2020 - Subpoenaed Equipment Not Yet Provided|MC EMS 2020 - Subpoenaed Equipment Not Yet Provided]]
** [[The Anomalies#MC EMS 2020 - Failure to Follow Basic Cyber Security Practices|MC EMS 2020 - Failure to Follow Basic Cyber Security Practices]]
** [[The Anomalies#MC EMS 2020 - Anonymous Logins|MC EMS 2020 - Anonymous Logins]]
** [[The Anomalies#MC EMS 2020 - Dual Boot System Discovered|MC EMS 2020 - Dual Boot System Discovered]]
** [[The Anomalies#MC EMS 2020 - Internet Connections to the EMS|MC EMS 2020 - Internet Connections to the EMS]]
* '''Undetected errors''' - End users, developers, or unrelated attackers may improperly alter data in the entity's information technology without visible evidence. Erroneous changes resulting from corrupted systems may not be readily detectable by users.
** [[The Anomalies#MC EMS 2020 - Subpoenaed Equipment Not Yet Provided|MC EMS 2020 - Subpoenaed Equipment Not Yet Provided]]
** [[The Anomalies#MC EMS 2020 - Election Management System Database Purged|MC EMS 2020 - Election Management System Database Purged]]
** [[The Anomalies#MC EMS 2020 - Election Files Deleted|MC EMS 2020 - Election Files Deleted]]
** [[The Anomalies#MC EMS 2020 - Corrupt Ballot Images|MC EMS 2020 - Corrupt Ballot Images]]
** [[The Anomalies#MC EMS 2020 - Missing Ballot Images|MC EMS 2020 - Missing Ballot Images]]
** [[The Anomalies#MC EMS 2020 - Operating System Logs Not Preserved|MC EMS 2020 - Operating System Logs Not Preserved]]
**

Latest revision as of 15:49, 27 August 2026

Risk Assessment

Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk

Attribute 8.14 - Management considers the types of risks that could impact the entity's information and information technology to provide a basis for identifying and analyzing risks related to information security. Information security risk is the risk to entity operations, assets, and personnel, as well as external parties, due to unauthorized access, use, disclosure, disruption, modification, or destruction of information or information technology. These risks may impact the information security objectives of confidentiality, integrity, and availability. Types of information security risk impacting each of these three objectives may include the following:

  • Unauthorized access - End users, developers, or unrelated attackers may compromise the confidentiality of a platform or software system by overriding controls to gain unauthorized access to the entity's information technology or use capabilities that exceed their rights in those systems.
  • Exploitation of personnel - Attacks, such as phishing attempts, that trick users into revealing information or giving an attacker access to a platform or software system.
  • Installation of malicious software - Installation of a program or file that intentionally attacks the entity's information technology by corrupting or stealing data, overwhelming a system with traffic, or locking the entity out. The objective of a malicious software (malware) attack may be to harm the entity, gain information, or obtain a financial gain.
  • Automated attacks - Attacks on information technology may be automated through mechanisms, such as bots, artificial intelligence, and machine learning software.
  • Undetected errors - End users, developers, or unrelated attackers may improperly alter data in the entity's information technology without visible evidence. Erroneous changes resulting from corrupted systems may not be readily detectable by users.
  • Threats to physical environment - Threats to the physical environment, such as fire, loss of electricity, loss of climate controls, or natural disasters, can result in the loss of information or information technology system damage or disruption. In addition, failure to appropriately limit physical access to information or an information technology system may also allow a malicious attacker to access or modify information.

>>>Navigational Buttons<<<


Jamie's Story

No examples are available to illustrate governance gaps for this attribute.

Election Anomalies

The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.

The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.

Arizona Senate Allegations

Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the Arizona Attorney General's Office 2020 General Election Investigation. This Green Book attribute applies given the Arizona Senate's concern that the 2020 election results may have been fraudulently reported, specifically for the following threats.