11.10
Control Activities
Principle 11 - Design General Control Activities over Information Technology
Attribute 11.10 - Security management is the ongoing process for mitigating information security risks as part of the entity's overall internal control system (sometimes referred to as a security management program). This ongoing process covers all components of internal control related to information security risks.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - 11.09
- Next Attribute - 11.11
Jamie's Story
No examples are available to illustrate governance gaps for this attribute.
Election Anomalies
Arizona Senate Allegations
Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the Arizona Attorney General's Office 2020 General Election Investigation. This Green Book attribute applies given the Arizona Senate's concern that the 2020 election related to the integrity of the data, which may have been compromised by lacks data security.
- Maricopa Election Management Server (2020)
- MC EMS 2020 - Election Management System Database Purged
- MC EMS 2020 - Election Files Deleted
- MC EMS 2020 - Corrupt Ballot Images
- MC EMS 2020 - Missing Ballot Images
- MC EMS 2020 - Failure to Follow Basic Cyber Security Practices
- MC EMS 2020 - Anonymous Logins
- MC EMS 2020 - Dual Boot System Discovered
- MC EMS 2020 - Operating System Logs Not Preserved
- MC EMS 2020 - Internet Connections to the EMS
