International Foundation for Electoral Systems
Kenya, the IEBC started the process of finding a certification and testing company but discovered that no
company was willing to certify the technology without access to manual processes, chain of custody,
source code review, procurement transparency, and other similar information. Certification was
ultimately not pursued.
There are various other types of testing
Types of Testing and Review Provided by the U.S.
processes that can also examine elements of
Department of Homeland Security
election technology development or use. Logic
Risk and vulnerability testing: A multi-week
and Accuracy (L&A) testing is the process by
probing of the entire system required to run an
which voting equipment is configured, tested,
election
and certified for accuracy prior to an election.
Cyber-infrastructure survey: An expert-led
Each component is tested to verify that it is
assessment accomplished through informal
fully functional and free from mechanical
interviews.
problems and that each voting unit contains
Cyber-resilience review: Helping election officials
the appropriate ballot styles for its designated
conduct their own self-assessments.
polling place. Penetration testing (pen tests)
consists of a variety of tools used to identify
Cyber-hygiene scans: Probing election systems
remotely and reporting vulnerabilities.
technology vulnerabilities, including port
scanning, vulnerability scanning (software and
firmware), packet sniffing, and review of log files. A risk-limiting post-election audit checks a random
sample of voted ballots, or voter-verifiable records, in search of strong evidence that the reported
election outcome was correct.101 If the reported outcome is incorrect, then the audit may lead to a full
hand re-count that reveals the correct election outcome. By design, once the audit finds strong evidence
that the reported outcome was correct, it can stop. Thus, the audit adapts to the facts of a particular
election. Following the 2016 elections in the U.S., and the designation of election systems as “critical
infrastructure,” the U.S. Department of Homeland Security designed a variety of testing and review
processes (outlined in the text box at right) that it has offered to states. However, these testing
processes are focused primarily on the technology system itself, and are subject to lengthy delays that
raise challenges for states seeking to implement changes ahead of elections.102
IFES aims to incorporate elements of existing testing processes within a straightforward, holistic testing
process that can help an EMB correct vulnerabilities in the system that could lead to known or unknown
manipulation of election data, system failure, or future legal challenges. The HEAT process will not be a
mechanism to approve or reject the decision to use a particular technology or a particular vendor,
although it can inform effective vendor relationships and cybertechnology supply chain threats, as well
as the interaction between different technology platforms that might be used in different parts of the
electoral process. A HEAT process can also help an EMB prepare for the resources and processes they
101
Mark Lindeman and Philip B. Stark “A Gentle Introduction to Risk-Limiting Audits,” IEEE Security and Privacy,
Special Issue on Electronic Voting, 2012, https://www.stat.berkeley.edu/~stark/Preprints/gentle12.pdf.
102
Tim Starks, “The latest 2018 election-hacking threat: 9-month wait for government help,” Politico, December
29, 2017, https://www.politico.com/story/2017/12/29/2018-election-hacking-threat-government-help231512?cid=apn.
28