Cybersecurity in Elections: Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies The US-CERT framework is detailed on the comprehensive NIST website. NIST also runs the Computer Security Resource Center, which keeps its 800-series publications (resources focused on cybersecurity) in one searchable archive. These publications range from targeted security recommendations, such as email protection or message authentication code algorithms, to best practices for employees and general frameworks. ISACA provides a framework for information systems security audits54 and a framework for balancing the risks and benefits of IT.55 The latter is based on five principles: 1) meeting stakeholder needs; 2) covering the enterprise end-to-end; 3) applying a single, integrated framework; 4) enabling a holistic approach; and 5) separating governance from management.56 The EU Agency for Network and Information Security (ENISA) and ISO have identified critical cyberthreats that must be addressed. ISO’s cybersecurity guidelines, which were produced through a joint committee with the International Electrotechnical Commission, includes a list of more than 50 threats, and ENISA publishes an annual “Threat Landscape” report identifying the top 15 cyberthreats that year.57 While some are more directly relevant to EMBs than others, all could be used to undermine the security and legitimacy of the electoral process. ENISA identified threats as diverse as information leakage, such as in the 2017 French elections, cyber espionage, such as the Russian involvement in the 2016 U.S. elections, ransomware, and insider threats.58 The diverse landscape of threats from inside and outside an organization demonstrate the need for comprehensive and systematic cybersecurity protection. d) Election Observer Guidelines As well as introducing new operational and security considerations, emerging election technology has also changed the observation of elections. When observation missions are unprepared to observe, analyze, and report on the use of new technology, the legitimacy of elections can be undermined by a lack of effective observation or inaccurate observations, especially in the event of disputed results. This can be particularly true for citizen observation missions that may lack the methodologies or capacity to properly observe technology processes in elections. One example of this is the 2017 Kenyan elections, when the opposition claimed technological malfeasance and manipulation had cost them the election.59 Citizen observers were the only ones able to verify the counting and results tabulation process, but the  Recover (develop/implement activities related to restoring capabilities if systems were impacted and increase resilience). 54 Shemlse Gebremedhin Kassa, “Information Systems Security Audit: An Ontological Framework,” ISACA Journal vol. 5, 2016, https://www.isaca.org/Journal/archives/2016/volume-5/Pages/information-systems-securityaudit.aspx. 55 “COBIT,” ISACA, http://www.isaca.org/cobit/pages/default.aspx. 56 ISACA, COBIT 5: A Business Framework for the Governance and Management of Enterprise IT, Executive Summary. 57 International Organization for Standardization and International Electrotechnical Commission, ISO/IEC 27005:2011, 2011; ENISA, ENISA Threat Landscape Report 2017, 2018. 58 ENISA, ENISA Threat Landscape Report 2017, 79-87. 59 “Kenya opposition leader Raila Odinga claims election fraud,” Financial Times, August 9, 2017, https://www.ft.com/content/2f795986-7cda-11e7-ab01-a13271d1ee9c. 13

Select target paragraph3