A Threat Analysis on UOCAVA Voting Systems
Overview
Lynne S. Rosenthal
lynne.rosenthal@nist.gov
NIST Voting Program
National Institute of Standards and Technology
EAC Standards Board Meeting February 26-27, 2009
A Threat Analysis on UOCAVA Voting Systems Overview Lynne S. - - PowerPoint PPT Presentation
A Threat Analysis on UOCAVA Voting Systems Overview Lynne S. Rosenthal lynne.rosenthal@nist.gov NIST Voting Program National Institute of Standards and Technology EAC Standards Board Meeting February 26-27, 2009 Todays Topics EAC/NIST
lynne.rosenthal@nist.gov
National Institute of Standards and Technology
EAC Standards Board Meeting February 26-27, 2009
2/ 26/ 2009 Page 2
2/ 26/ 2009 Page 3
2/ 26/ 2009 Page 4
Network and system threats and vulnerabilities
Sophisticated network-based attacks and defenses
Secure system and network management
VVSG and associated tests
Technical research items
UOCAVA voting
2/ 26/ 2009 Page 5
Postal mail, telephone, fax, e-mail, web-based
Voter registration/ballot request (e.g., FPCA)
Ballot delivery
Ballot return
2/ 26/ 2009 Page 6
Analysis based on NIST SP 800-30 Risk Management Guide for Information Technology Systems
Both technical and procedural controls
Security controls taken from NIST SP 800-53 Recommended Security Controls for Federal Information Systems
2/ 26/ 2009 Page 7
2/ 26/ 2009 Page 8
2/ 26/ 2009 Page 9
2/ 26/ 2009 Page 10
2/ 26/ 2009 Page 11
available at:
2/ 26/ 2009 Page 12
Lynne S. Rosenthal National Institute of Standards and Technology lynne.rosenthal@nist.gov