International Foundation for Electoral Systems Kenya, the IEBC started the process of finding a certification and testing company but discovered that no company was willing to certify the technology without access to manual processes, chain of custody, source code review, procurement transparency, and other similar information. Certification was ultimately not pursued. There are various other types of testing Types of Testing and Review Provided by the U.S. processes that can also examine elements of Department of Homeland Security election technology development or use. Logic Risk and vulnerability testing: A multi-week and Accuracy (L&A) testing is the process by probing of the entire system required to run an which voting equipment is configured, tested, election and certified for accuracy prior to an election. Cyber-infrastructure survey: An expert-led Each component is tested to verify that it is assessment accomplished through informal fully functional and free from mechanical interviews. problems and that each voting unit contains Cyber-resilience review: Helping election officials the appropriate ballot styles for its designated conduct their own self-assessments. polling place. Penetration testing (pen tests) consists of a variety of tools used to identify Cyber-hygiene scans: Probing election systems remotely and reporting vulnerabilities. technology vulnerabilities, including port scanning, vulnerability scanning (software and firmware), packet sniffing, and review of log files. A risk-limiting post-election audit checks a random sample of voted ballots, or voter-verifiable records, in search of strong evidence that the reported election outcome was correct.101 If the reported outcome is incorrect, then the audit may lead to a full hand re-count that reveals the correct election outcome. By design, once the audit finds strong evidence that the reported outcome was correct, it can stop. Thus, the audit adapts to the facts of a particular election. Following the 2016 elections in the U.S., and the designation of election systems as “critical infrastructure,” the U.S. Department of Homeland Security designed a variety of testing and review processes (outlined in the text box at right) that it has offered to states. However, these testing processes are focused primarily on the technology system itself, and are subject to lengthy delays that raise challenges for states seeking to implement changes ahead of elections.102 IFES aims to incorporate elements of existing testing processes within a straightforward, holistic testing process that can help an EMB correct vulnerabilities in the system that could lead to known or unknown manipulation of election data, system failure, or future legal challenges. The HEAT process will not be a mechanism to approve or reject the decision to use a particular technology or a particular vendor, although it can inform effective vendor relationships and cybertechnology supply chain threats, as well as the interaction between different technology platforms that might be used in different parts of the electoral process. A HEAT process can also help an EMB prepare for the resources and processes they 101 Mark Lindeman and Philip B. Stark “A Gentle Introduction to Risk-Limiting Audits,” IEEE Security and Privacy, Special Issue on Electronic Voting, 2012, https://www.stat.berkeley.edu/~stark/Preprints/gentle12.pdf. 102 Tim Starks, “The latest 2018 election-hacking threat: 9-month wait for government help,” Politico, December 29, 2017, https://www.politico.com/story/2017/12/29/2018-election-hacking-threat-government-help231512?cid=apn. 28

Select target paragraph3