International Foundation for Electoral Systems
fundamental so that changes in procedure – for example, switching to paper ballots in case of a power
outage or security breach – are not perceived as suspicious in and of themselves.
c)
Cybersecurity Instruments and Frameworks
The field of cybersecurity in elections is still emerging, both in national legislation and in international
jurisprudence and standards. Apart from the Council of Europe’s 2006 Cybercrime Convention
(Budapest Convention), there are no other binding international instruments at present that directly
tackle prevention of and punishment for cyberattacks.46 Countries often have general security
regulations that do not cover all cybersecurity-related issues, or they are scattered in multiple pieces of
legislation and government regulations, some of which may be outdated. A coherent legal framework
for cybersecurity is important. For example, Ukraine passed a Law on Cybersecurity, which took effect in
May 2018, in response to its dire need to systematically handle cyberattacks, such as the (Not)Petya
malware attacks of June 2017.47
Several high-level policy institutes have developed cybersecurity frameworks to systematically address
cyberthreats and vulnerabilities in any complex system. These organizations include the U.S. Computer
Emergency Readiness Team (US-CERT),48 NIST,49 the information systems non-profit ISACA,50 and the
International Organization for Standardization (ISO).51 In the absence of election-specific cybersecurity
standards, these general frameworks may be useful for EMBs.
Cybersecurity frameworks are typically organized using a functional approach (that is, breaking down
processes into functions). NIST, together with US-CERT,52 identified a functional approach in its
framework in five steps that is now widely used within the cybersecurity community: identify, protect,
detect, respond, and recover.53
46
“Budapest Convention and related standards,” Council of Europe, https://www.coe.int/web/cybercrime/thebudapest-convention.
47
The original ransomware attack known as “Petya” held hostage data from several companies and demanded a
ransom to release it. A number of cybersecurity analysts maintain that the newer versions were instead aimed at
causing damage. Olivia Solon and Alex Hern, “’Petya’ ransomware attack: what is it and how can it be stopped?”
The Guardian, June 28, 2017, https://www.theguardian.com/technology/2017/jun/27/petya-ransomware-cyberattack-who-what-why-how.
48
US-CERT, https://www.us-cert.gov/.
49
National Institute of Standards and Technology, https://www.nist.gov/.
50
ISACA, https://www.isaca.org/Pages/default.aspx?gclsrc=aw.ds.
51
ISO, https://www.iso.org/home.html.
52
US-CERT, https://www.us-cert.gov/.
53
National Institute of Standards and Technology, Framework for Improving Critical Infrastructure Cybersecurity,
ver. 1.1, 2018, 3, https://www.us-cert.gov/ccubedvp/cybersecurity-framework.
Identify (develop organizational understanding to manage risk),
Protect (develop/implement safeguards),
Detect (develop/implement activities to recognize if an event is related to cybersecurity),
Respond (develop/implement actions to contain the impact of a cybersecurity event) and
12