Cybersecurity in Elections:
Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies
The US-CERT framework is detailed on the comprehensive NIST website. NIST also runs the Computer
Security Resource Center, which keeps its 800-series publications (resources focused on cybersecurity)
in one searchable archive. These publications range from targeted security recommendations, such as
email protection or message authentication code algorithms, to best practices for employees and
general frameworks. ISACA provides a framework for information systems security audits54 and a
framework for balancing the risks and benefits of IT.55 The latter is based on five principles: 1) meeting
stakeholder needs; 2) covering the enterprise end-to-end; 3) applying a single, integrated framework; 4)
enabling a holistic approach; and 5) separating governance from management.56
The EU Agency for Network and Information Security (ENISA) and ISO have identified critical
cyberthreats that must be addressed. ISO’s cybersecurity guidelines, which were produced through a
joint committee with the International Electrotechnical Commission, includes a list of more than 50
threats, and ENISA publishes an annual “Threat Landscape” report identifying the top 15 cyberthreats
that year.57 While some are more directly relevant to EMBs than others, all could be used to undermine
the security and legitimacy of the electoral process. ENISA identified threats as diverse as information
leakage, such as in the 2017 French elections, cyber espionage, such as the Russian involvement in the
2016 U.S. elections, ransomware, and insider threats.58 The diverse landscape of threats from inside and
outside an organization demonstrate the need for comprehensive and systematic cybersecurity
protection.
d)
Election Observer Guidelines
As well as introducing new operational and security considerations, emerging election technology has
also changed the observation of elections. When observation missions are unprepared to observe,
analyze, and report on the use of new technology, the legitimacy of elections can be undermined by a
lack of effective observation or inaccurate observations, especially in the event of disputed results. This
can be particularly true for citizen observation missions that may lack the methodologies or capacity to
properly observe technology processes in elections. One example of this is the 2017 Kenyan elections,
when the opposition claimed technological malfeasance and manipulation had cost them the election.59
Citizen observers were the only ones able to verify the counting and results tabulation process, but the
Recover (develop/implement activities related to restoring capabilities if systems were impacted and increase
resilience).
54
Shemlse Gebremedhin Kassa, “Information Systems Security Audit: An Ontological Framework,” ISACA Journal
vol. 5, 2016, https://www.isaca.org/Journal/archives/2016/volume-5/Pages/information-systems-securityaudit.aspx.
55
“COBIT,” ISACA, http://www.isaca.org/cobit/pages/default.aspx.
56
ISACA, COBIT 5: A Business Framework for the Governance and Management of Enterprise IT, Executive
Summary.
57
International Organization for Standardization and International Electrotechnical Commission, ISO/IEC
27005:2011, 2011; ENISA, ENISA Threat Landscape Report 2017, 2018.
58
ENISA, ENISA Threat Landscape Report 2017, 79-87.
59
“Kenya opposition leader Raila Odinga claims election fraud,” Financial Times, August 9, 2017,
https://www.ft.com/content/2f795986-7cda-11e7-ab01-a13271d1ee9c.
13