MC EMS 2020 - Operating System Logs Not Preserved

From Corrective Action Plan AZ

In your exploration of election-related anomalies, you are here:

This page seeks to explain potential governance gaps with respect to allegations from the Arizona Senate, specifically for allegation #3 Maricopa County Election Department - Election Management System anomalies. These were investigated by the Arizona Attorney General's Office 2020 General Election Investigation Report. This topic is listed on Election Anomalies page, which lists various election-related anomalies that illustrate poor governance.

Governance Gaps are reported on and compared to a standard so that you may visualize how poorly managed County services can have an adverse impact without any criminal wrongdoing. We chose the United States Government Accountability Office's (GAO) Standards for Internal Control in the Federal Government (also known as the Green Book) because it represents the ideal standard for governance practices since it is specifically written for government entities, not the business sector. Maricopa County has no obligation or commitments to adhere to any governance-related standards, including the Green Book. Regardless, the Green Book is a representation of what good governance looks like and deviations from that standard are worthy of consideration, not prosecution.

The Governance Gap Assessment Team are not IT security experts. The technical aspects of the IT configuration are not being disputed. The assessment for governance gaps sought to understand how data and information was being treated with respect to the US GAO's Standards for Internal Control in the Federal Government.

Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County Election Department - Election Management Server (EMS) issues.

MC EMS 2020 - Operating System Logs Not Preserved

Governance gaps were identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations #3 Maricopa County Election Department - Election Management Server (EMS) issues, which consisted of ten separate allegations. MC EMS 2020 - Election Management System Database Purged is an assessment of one of the ten sub-allegations associated with the EMS.

Allegation

Cyber Ninjas stated the Window event logs on the EMS server contained windows security event logs. This log was restricted by policy set by County Elections at a file size of approximately 20mb (20,480kb). This logging was set to overwrite once file exceeded size limits.

Relevant Inspector Notes
  • Election Officials explain "the EMS server could be remotely accessed via the local area network within the air gap system."
  • The EMS server was often accessed from the EMS Admin Station located within the BTC.
  • Three EMS server access events were identified, with justification provided by the Election Department.
  • On April 12, 2021, the Election Department identifies Brian Ramirez, a County Elections Staff Member, as having access. The county asserts that the second individual with Brian Ramirez is a coworker, but was not identified.
Inspector's Finding

Agents have a pending request to review log entries with Election Officials. This review will allow for a better understanding of the logs, and help further identify why there are discrepancies between the logs identified by Cyber Ninjas and the logs notated by PacketWatch and County Elections. Additionally, further questions will be asked regarding what actions were taking place on 2/11/21.

Governance Gaps Assessment
  • Consistent with all allegations, this allegations should not have occurred had MC leadership respected the Arizona's role as an oversight entity.
  • The policy for limiting the file size for Windows event logs appears to lack documentation; none was noted in the AZ AG's inspector's report.
  • The risk of impeding investigations in an effort to save digital space seems misguided. Worse, the risk was intentionally disregarded and the overwrite feature was a convenient method to automatically eliminate prior Windows security logged events.
  • No identification of this as an internal control risk was initiated. Hence, there was no internal investigation or corrective actions to prevent recurrence.

Potential Governance Gap(s):

  • Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
    • Attribute(s):
  • Principle 2 - Exercise Oversight Responsibility
    • Attribute(s):
  • Principle 3 - Establish Structure, Responsibility, and Authority
    • Attribute(s):
  • Principle 4 - Demonstrate Commitment to Competence
    • Attribute(s):
  • Principle 5 - Enforce Accountability
    • Attribute(s):
  • Principle 6 - Define Objectives and Risk Tolerances
    • Attribute(s):
  • Principle 7 - Identify, Analyze, and Respond to Risks
    • Attribute(s):
  • Principle 8 - Assess Fraud, Improper Payment, and Information
    • Attribute(s):
  • Principle 9 - Identify, Analyze, and Respond to Change
    • Attribute(s):
  • Principle 10 - Design Control Activities
    • Attribute(s):
  • Principle 11 - Design General Control Activities over Information
    • Attribute(s):
  • Principle 12 - Implement Control Activities
    • Attribute(s):
  • Principle 13 - Use Quality Information
    • Attribute(s):
  • Principle 14 - Communicate Internally
    • Attribute(s):
  • Principle 15 - Communicate Externally
    • Attribute(s):
  • Principle 16 - Perform Monitoring Activities
    • Attribute(s):
  • Principle 17 - Evaluate Issues and Remediate Deficiencies
    • Attribute(s):