Maricopa Election Management Server (2020): Difference between revisions

From Corrective Action Plan AZ
No edit summary
Line 5: Line 5:
=== List of Allegations ===
=== List of Allegations ===
The following allegations were submitted by the Arizona Senate in 2021 to the Arizona Attorney General for investigation:
The following allegations were submitted by the Arizona Senate in 2021 to the Arizona Attorney General for investigation:
# Election Management System Database Purged
# Election Management System Database Purged
# Election Files Deleted
# Election Files Deleted
Line 17: Line 16:
# Internet Connections to the EMS
# Internet Connections to the EMS


=== Election Management System Database Purged ===
==== Election Management System Database Purged ====
<u>Allegation</u>
 
The Elections Management System (EMS) database was allegedly purged of all the details associated with the 2020 General Election. The allegation originated from Cyber Ninjas. They explain that all election results were cleared by a Results Talley and Reporting Admin on 2/2/21 at 1714, which was the "evening before" the Pro V & V Audit was scheduled to officially start.
 
<u>Relevant Inspector Notes</u>
 
The AZ AG's inspector reports the following statement from the MC Director of Information Technology, Nate Young, "the server database was required to be clean for the logic and accuracy tests completed by Pro V&V and SLI Compliance on February 1, 2021.
 
<u>Inspector's Finding</u>
 
'''Indeterminate.''' Agents are pending a date to review archived data to ensure all elections files are present.
 
<u>Governance Gap Assessment:</u>
 
As of the winter of 2021, all of the election files were still not available for inspection by the AZ AG's inspectors, after more than one year had elapsed since the General Election of 2121. The report states follow up is needed but does not identify any one person accountable for the follow up. This issue remains unresolved based on the contents.
 
==== Election Files Deleted ====
<u>Allegation</u>
 
The Basic Cyber Security Practices were allegedly not followed. The allegation originated from Cyber Ninjas. They explained the Department of Homeland Security's Cybersecurity & Infrastructure Security Agency (CISA) has guidelines, which MC was not following.
 
<u>Relevant Inspector Notes</u>
 
* The EMS server along other election equipment is configured in an air gapped standalone system (no outside connectivity outside of the control access room).
* CISA guidelines are not applicable because of the air gapped configuration.
* The EMS server along with the other election equipment resides inside a controlled access room under 24-hour video monitoring.
* A two-person rule is required to enter the room.
 
<u>Inspector's Finding</u>
 
Unfounded Allegation. The inspector found no indication of malicious or criminal acts performed by Maricopa County Elections Officials.
 
<u>Governance Gaps Assessment</u>
 
* The AZ AG's inspector explains the equipment is under 24-hour surveillance. However, the inspector did not claim to have reviewed the surveillance videos. In fact, the surveillance videos were likely unavailable given the common practice to overwrite the video data with new surveillance video data after a sufficient time has elapsed to retrieve video data from the suspected time frame. Without an independent review of the surveillance video by the inspector, there seems to be an overreliance on the simple existence of the 24-hour camera to make the assertion of "no malicious or criminal acts.
* The AZ AG's inspector relied on the MC leadership team claiming that a two-person rule is required to enter the room. There is no indication that the 24-hour video data was reviewed to confirm the two-person rule was always applied.
* The AZ AG's inspector had already noted that procedure violations had occurred during drop box collections. It would have seemed critical for the inspector to claim "no indication of malicious or criminal acts" if objective data was not reviewed to confirm compliance with the two-person rule.
* The AZ AG's inspector was told of a two-person rule. During the inspector's investigation of the drop box collection allegations, the two-person rule was more specific. One member of each political party (i.e., Democrat and Republican) had to be assigned to a collection team. The consequence of malicious and criminal performed on the EMS would be far more serious than a drop box collection, but the teaming requirement is less restrictive. In this case, the two-person rule is being questioned as being too lenient for the associated risk.
* The AZ AG's inspector was told the Maricopa County within compliance of state and federal law as it pertains to these areas. Federal laws and Arizona Statutes are essentially policy statements, which affected entities are obligated to follow. Laws and statutes do not typically provide the necessary details form implementation of the laws and statutes. The inspector did not identify any IT standards for data security that MC Elections were following. They only claim to be in compliance with laws and statutes without any standard.
 
==== Corrupt Ballot Images ====
<u>Allegation</u>
 
 
<u>Relevant Inspector Notes</u>
 
 
<u>Inspector's Finding</u>
 
 
<u>Governance Gaps Assessment</u>
 
x
 
==== Missing Ballot Images ====
<u>Allegation</u>
 
 
<u>Relevant Inspector Notes</u>
 
 
<u>Inspector's Finding</u>
 
 
<u>Governance Gaps Assessment</u>
 
x
 
==== Failure to Follow Basic Cyber Security Practices ====
<u>Allegation</u>
 
 
<u>Relevant Inspector Notes</u>
 
 
<u>Inspector's Finding</u>
 
 
<u>Governance Gaps Assessment</u>
 
x
 
==== Subpoenaed Equipment Not Yet Provided ====
<u>Allegation</u>
 
 
<u>Relevant Inspector Notes</u>
 
 
<u>Inspector's Finding</u>
 
 
<u>Governance Gaps Assessment</u>
 
x
 
==== Anonymous Logins ====
<u>Allegation</u>
 
 
<u>Relevant Inspector Notes</u>
 
 
<u>Inspector's Finding</u>
 
 
<u>Governance Gaps Assessment</u>
 
x
 
==== Dual Boot System Discovered ====
<u>Allegation</u>
 
 
<u>Relevant Inspector Notes</u>
 
 
<u>Inspector's Finding</u>
 
 
<u>Governance Gaps Assessment</u>
 
x
 
==== Operating System Logs Not Preserved ====
<u>Allegation</u>
 
 
<u>Relevant Inspector Notes</u>
 
 
<u>Inspector's Finding</u>
 
 
<u>Governance Gaps Assessment</u>


=== Election Files Deleted ===
x


=== Corrupt Ballot Images ===
==== Internet Connections to the EMS ====
<u>Allegation</u>


=== Missing Ballot Images ===


=== Failure to Follow Basic Cyber Security Practices ===
<u>Relevant Inspector Notes</u>


=== Subpoenaed Equipment Not Yet Provided ===


=== Anonymous Logins ===
<u>Inspector's Finding</u>


=== Dual Boot System Discovered ===


=== Operating System Logs Not Preserved ===
<u>Governance Gaps Assessment</u>


=== Internet Connections to the EMS ===
x

Revision as of 19:43, 26 August 2026

This page seeks to explain Maricopa County Election Department - Election Management System anomalies as reported by the Arizona Attorney General's Office 2020 General Election Investigation Report. This topic is listed on Election Anomalies page, which lists various election-related anomalies that illustrate poor governance.

Governance Gaps are reported on and compared to a standard so that you may visualize how poorly managed County services can have an adverse impact without any criminal wrongdoing. We chose the United States Government Accountability Office's (GAO) Standards for Internal Control in the Federal Government (also known as the Green Book) because it represents the ideal standard for governance practices since it is specifically written for government entities, not the business sector. Maricopa County has no obligation or commitments to adhere to any governance-related standards, including the Green Book. Regardless, the Green Book is a representation of what good governance looks like and deviations from that standard are worthy of consideration, not prosecution.

List of Allegations

The following allegations were submitted by the Arizona Senate in 2021 to the Arizona Attorney General for investigation:

  1. Election Management System Database Purged
  2. Election Files Deleted
  3. Corrupt Ballot Images
  4. Missing Ballot Images
  5. Failure to Follow Basic Cyber Security Practices
  6. Subpoenaed Equipment Not Yet Provided
  7. Anonymous Logins
  8. Dual Boot System Discovered
  9. Operating System Logs Not Preserved
  10. Internet Connections to the EMS

Election Management System Database Purged

Allegation

The Elections Management System (EMS) database was allegedly purged of all the details associated with the 2020 General Election. The allegation originated from Cyber Ninjas. They explain that all election results were cleared by a Results Talley and Reporting Admin on 2/2/21 at 1714, which was the "evening before" the Pro V & V Audit was scheduled to officially start.

Relevant Inspector Notes

The AZ AG's inspector reports the following statement from the MC Director of Information Technology, Nate Young, "the server database was required to be clean for the logic and accuracy tests completed by Pro V&V and SLI Compliance on February 1, 2021.

Inspector's Finding

Indeterminate. Agents are pending a date to review archived data to ensure all elections files are present.

Governance Gap Assessment:

As of the winter of 2021, all of the election files were still not available for inspection by the AZ AG's inspectors, after more than one year had elapsed since the General Election of 2121. The report states follow up is needed but does not identify any one person accountable for the follow up. This issue remains unresolved based on the contents.

Election Files Deleted

Allegation

The Basic Cyber Security Practices were allegedly not followed. The allegation originated from Cyber Ninjas. They explained the Department of Homeland Security's Cybersecurity & Infrastructure Security Agency (CISA) has guidelines, which MC was not following.

Relevant Inspector Notes

  • The EMS server along other election equipment is configured in an air gapped standalone system (no outside connectivity outside of the control access room).
  • CISA guidelines are not applicable because of the air gapped configuration.
  • The EMS server along with the other election equipment resides inside a controlled access room under 24-hour video monitoring.
  • A two-person rule is required to enter the room.

Inspector's Finding

Unfounded Allegation. The inspector found no indication of malicious or criminal acts performed by Maricopa County Elections Officials.

Governance Gaps Assessment

  • The AZ AG's inspector explains the equipment is under 24-hour surveillance. However, the inspector did not claim to have reviewed the surveillance videos. In fact, the surveillance videos were likely unavailable given the common practice to overwrite the video data with new surveillance video data after a sufficient time has elapsed to retrieve video data from the suspected time frame. Without an independent review of the surveillance video by the inspector, there seems to be an overreliance on the simple existence of the 24-hour camera to make the assertion of "no malicious or criminal acts.
  • The AZ AG's inspector relied on the MC leadership team claiming that a two-person rule is required to enter the room. There is no indication that the 24-hour video data was reviewed to confirm the two-person rule was always applied.
  • The AZ AG's inspector had already noted that procedure violations had occurred during drop box collections. It would have seemed critical for the inspector to claim "no indication of malicious or criminal acts" if objective data was not reviewed to confirm compliance with the two-person rule.
  • The AZ AG's inspector was told of a two-person rule. During the inspector's investigation of the drop box collection allegations, the two-person rule was more specific. One member of each political party (i.e., Democrat and Republican) had to be assigned to a collection team. The consequence of malicious and criminal performed on the EMS would be far more serious than a drop box collection, but the teaming requirement is less restrictive. In this case, the two-person rule is being questioned as being too lenient for the associated risk.
  • The AZ AG's inspector was told the Maricopa County within compliance of state and federal law as it pertains to these areas. Federal laws and Arizona Statutes are essentially policy statements, which affected entities are obligated to follow. Laws and statutes do not typically provide the necessary details form implementation of the laws and statutes. The inspector did not identify any IT standards for data security that MC Elections were following. They only claim to be in compliance with laws and statutes without any standard.

Corrupt Ballot Images

Allegation


Relevant Inspector Notes


Inspector's Finding


Governance Gaps Assessment

x

Missing Ballot Images

Allegation


Relevant Inspector Notes


Inspector's Finding


Governance Gaps Assessment

x

Failure to Follow Basic Cyber Security Practices

Allegation


Relevant Inspector Notes


Inspector's Finding


Governance Gaps Assessment

x

Subpoenaed Equipment Not Yet Provided

Allegation


Relevant Inspector Notes


Inspector's Finding


Governance Gaps Assessment

x

Anonymous Logins

Allegation


Relevant Inspector Notes


Inspector's Finding


Governance Gaps Assessment

x

Dual Boot System Discovered

Allegation


Relevant Inspector Notes


Inspector's Finding


Governance Gaps Assessment

x

Operating System Logs Not Preserved

Allegation


Relevant Inspector Notes


Inspector's Finding


Governance Gaps Assessment

x

Internet Connections to the EMS

Allegation


Relevant Inspector Notes


Inspector's Finding


Governance Gaps Assessment

x