All bodies  ›  Office of Voting Systems Technology Assessment  ›  California Use Procedures

OVSTA

California Use Procedures

Liberty Vote Democracy Suite 5.19

Office of Voting Systems Technology Assessment · vendors-dominion-ds519-ds519use-proc · Use procedures · Liberty Vote Systems

Read the report at Liberty Vote Systems ↗

® Democracy Suite Use Procedures Version: 5.19::4 June 18, 2024 Table of Contents Chapter 1: Introduction . . . . . . . . . . . . . . . . . . . . . . . . 1 1.1 System Description and Components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 ® 1.1.1 ImageCast Evolution (ICE) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 ® 1.1.2 ImageCast Central (ICC) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 ® 1.1.3 ImageCast Precinct 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 1.1.4 Election Management System (EMS) . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6 ® 1.1.5 ImageCast X (ICX) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 1.2 Equipment Cleaning/Disinfecting Guidelines . . . . . . . . . . . . . . . . . . . . . . . 9 ® 1.2.1 Instructions for Cleaning and Disinfecting an ImageCast Tabulator or ICX Touchscreen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 1.3 Terms and Definitions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 1.4 Use Procedure Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 Chapter 2: Ballot Definition . . . . . . . . . . . . . . . . . . 22 2.1 Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 2.2 Ballot Artwork Source Files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 2.3 Paper and Printing Specifications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 ® 2.4 ImageCast Ballot Stock Selection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23 2.5 Approved Ballot Paper Stocks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24 Chapter 3: System Installation and Configuration 25 3.1 Hardware Requirements and Specifications . . . . . . . . . . . . . . . . . . . . . . . . 25 3.1.1 Election Management System Hardware Requirements . . . . . . . . . . . 25 ® 3.1.2 ImageCast Central Hardware Requirements . . . . . . . . . . . . . . . . . . . 25 ® 3.1.3 ImageCast Evolution Hardware Requirements . . . . . . . . . . . . . . . . 26 ® 3.1.4 ImageCast Precinct 2 Hardware Requirements . . . . . . . . . . . . . . . . 26 3.1.5 ImageCast® X Hardware Requirements . . . . . . . . . . . . . . . . . . . . . . . . 27 3.2 Hardware and Network Set-up and Configuration . . . . . . . . . . . . . . . . . . 27 3.2.1 Air-gap Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29 3.2.1.1 Air-gap Configuration Details . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30 3.2.1.2 Performing Cryptographic Erase on Standard Server . . . . . . . . . 30 3.2.1.3 Dell Data Wipe (Dell 3400 Computers) . . . . . . . . . . . . . . . . . . . . . . 33 3.2.1.4 Dell Data Wipe (Dell 7050/7060 Computers with Solid State Drive SSD) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 6/18/2024 i Version: 5.19::4 Table of Contents 3.2.1.5 Dell Data Wipe Instructions (Dell Precision 3460 XE) . . . . . . . . . 33 3.2.1.6 Dell Data Wipe Instructions (Dell Optiplex XE4) . . . . . . . . . . . . . 34 3.2.1.7 Connect Equipment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34 3.2.1.8 Record Service Tags . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34 3.3 Upgrade EMS and Tabulators . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35 3.3.1 Before Beginning the Upgrade . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35 3.3.2 Upgrading the EMS Standard Server . . . . . . . . . . . . . . . . . . . . . . . . . . 36 3.3.2.1 Standard Server Checklist . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36 3.3.2.2 Installing Lifecycle Controller, BIOS Updates, and Drivers . . . . 36 3.3.2.3 Configuring BIOS, iDRAC and Verifying RAID Configuration/En- abling Self-Encrypting Drives (EMS Standard Server) . . . . . . . . . . . . . . . 37 3.3.2.4 Creating a Security Key . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38 3.3.2.5 Enabling Secure Boot . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 39 3.3.2.6 Configuring the Thermal Settings . . . . . . . . . . . . . . . . . . . . . . . . . 39 3.3.2.7 Pre-Image Deployment BIOS Configuration . . . . . . . . . . . . . . . . 40 3.3.2.8 Deploying the Image on the EMS Standard Server . . . . . . . . . . . 40 3.3.2.9 Activating Windows on the EMS Standard Server . . . . . . . . . . . . . 41 3.3.2.10 Enabling Client User Accounts on the EMS Standard Server . . 42 3.3.2.11 Changing User Passwords on the EMS Standard Server . . . . . . 42 3.3.2.12 Applying Cepstral Licenses on the EMS Standard Server . . . . . 43 3.3.2.13 Verifying Time Zone, Date and Time (EMS Standard Server) . 43 3.3.2.14 Rerunning the Data Center Manager (EMS Standard Server) . 44 3.3.2.15 Downloading and Applying Windows Defender Updates . . . . . . 45 3.3.2.16 Exporting the Adjudication Client Certificate from the Local Ma- chine Certificate Store . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45 3.3.2.17 Importing the Adjudication Client Certificate to the Current User Certificate Store . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46 3.3.2.18 Applying Hardening (EMS Standard Server) . . . . . . . . . . . . . . . . 47 3.3.2.19 Applying Post Hardening BIOS Settings (EMS Standard Server) . 48 3.3.3 Upgrading the EMS Client Workstation . . . . . . . . . . . . . . . . . . . . . . . 48 3.3.3.1 EMS Client Workstation Checklist . . . . . . . . . . . . . . . . . . . . . . . . . 49 3.3.3.2 Configuring the BIOS Settings on the EMS Client Workstation . 49 3.3.3.3 Deploying Image (Windows 11 Computers) . . . . . . . . . . . . . . . . . . 51 6/18/2024 ii Version: 5.19::4 Table of Contents 3.3.3.4 Updating BIOS (Windows 11 Computers) . . . . . . . . . . . . . . . . . . . . 52 3.3.3.5 Removing Unused Accounts (EMS Client Workstation) . . . . . . . . 52 3.3.3.6 Activating Windows . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53 3.3.3.7 Verifying and Installing System Drivers in Device Manager . . . . . 53 3.3.3.8 Setting the Correct Time Zone . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54 3.3.3.9 Changing the Computer Name (EMS Client, ADJ Client, and ICC Cli- ent) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54 3.3.3.10 Connecting Computers to the Network Switch (EMS Client, ADJ Client, ICC) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55 3.3.3.11 Downloading and Applying Windows Defender Updates . . . . . . 55 3.3.3.12 Adjusting Autoplay Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56 3.3.3.13 Installing Trusted Server Certificate . . . . . . . . . . . . . . . . . . . . . . . 56 3.3.3.14 Applying BitLocker Encryption (EMS Client Workstation) . . . . 56 3.3.3.15 Applying Hardening (EMS Client Workstation) . . . . . . . . . . . . . . 56 3.3.3.16 Configuring Post Hardening BIOS (EMS Client Workstation) . . 57 3.3.4 Upgrading the Adjudication Client Workstation . . . . . . . . . . . . . . . . . 57 3.3.4.1 Adjudication Client Workstation Checklist . . . . . . . . . . . . . . . . . . . 57 3.3.4.2 Configuring the BIOS on Windows 11 Adjudication Workstation 58 3.3.4.3 Deploying the Image on the Adjudication Workstation . . . . . . . . 59 3.3.4.4 Updating BIOS (Windows 11 Computers) . . . . . . . . . . . . . . . . . . . 60 3.3.4.5 Configuring the Post Image Deployment BIOS on the EMS Adjudi- cation Workstation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60 3.3.4.6 Activating Windows 11 on the EMS Adjudication Workstation . . 61 3.3.4.7 Removing Unused Accounts (EMS Adjudication Workstation) . . 61 3.3.4.8 Updating the Windows Registry . . . . . . . . . . . . . . . . . . . . . . . . . . 62 3.3.4.9 Clearing the Cache in Microsoft Edge and Accessing the Adjudica- tion Application . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62 3.3.4.10 Creating an Adjudication Desktop Shortcut . . . . . . . . . . . . . . . . 63 3.3.4.11 Verifying and Installing System Drivers in Device Manager on the Adjudication Workstation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64 3.3.4.12 Set Screen Orientation (ADJ Client) . . . . . . . . . . . . . . . . . . . . . . 64 3.3.4.13 Importing the Adjudication Client Certificate to the Current User 65 3.3.4.14 Applying BitLocker Encryption (Adjudication Client Workstation) 6/18/2024 iii Version: 5.19::4 Table of Contents 66 3.3.4.15 Changing the Computer Name on the Adjudication Workstation . 66 3.3.4.16 Connecting the EMS Adjudication Workstation to the Network Switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66 3.3.4.17 Configuring the Report Printer for the EMS Adjudication Worksta- tion . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66 3.3.4.18 Downloading and Applying Windows Defender Updates for the EMS Adjudication Workstation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67 3.3.4.19 Applying Hardening to the EMS Adjudication Workstation . . . . 67 3.3.4.20 Resetting Regional Date/Time Settings on the EMS Adjudication Workstation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68 3.3.5 Upgrading the ImageCast Voter Activation Workstation . . . . . . . . . 68 3.3.5.1 ICVA Workstation Checklist . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68 3.3.5.2 Configuring the BIOS on the ICVA Workstation . . . . . . . . . . . . . 69 3.3.5.3 Deploying the Image on the ICVA Workstation . . . . . . . . . . . . . . 70 3.3.5.4 Updating BIOS (Windows 11 Computers) . . . . . . . . . . . . . . . . . . . . 71 3.3.5.5 Activating Windows on the ICVA Workstation . . . . . . . . . . . . . . . . 71 3.3.5.6 Verifying and Installing System Drivers in Device Manager on the ICVA Workstation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72 3.3.5.7 Updating the BIOS on the ICVA Workstation . . . . . . . . . . . . . . . . . 73 3.3.5.8 Changing the Computer Name on the ICVA Client Workstation . 73 3.3.5.9 Configuring the Report Printer for the ICVA Workstation . . . . . . 74 3.3.5.10 Downloading and Applying Windows Defender Updates for the ICVA Workstation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74 3.3.5.11 Applying BitLocker Encryption (ICVA Workstation) . . . . . . . . . . 74 3.3.5.12 Applying Hardening to the ICVA Workstation . . . . . . . . . . . . . . . 75 3.3.5.13 Configuring the Post Hardening BIOS on the ICVA Workstation . 75 3.3.5.14 Resetting Regional Date/Time Settings on the ICVA Workstation 75 3.3.6 Upgrading the ImageCast Central Client Workstation . . . . . . . . . . . . 76 3.3.6.1 ICC Client Workstation Checklist . . . . . . . . . . . . . . . . . . . . . . . . . . . 76 3.3.6.2 Configuring the BIOS on the ICC Client Workstation . . . . . . . . . . 77 3.3.6.3 Deploying the Image on the ICC Client Workstation (Windows 11 6/18/2024 iv Version: 5.19::4 Table of Contents Computers) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80 3.3.6.4 Updating BIOS (Windows 11 Computers) . . . . . . . . . . . . . . . . . . . . 81 3.3.6.5 Activating Windows on the ICC Client Workstation . . . . . . . . . . 82 3.3.6.6 Removing Unused User Accounts on the ICC Client Workstation . . 83 3.3.6.7 Setting the Correct Time Zone . . . . . . . . . . . . . . . . . . . . . . . . . . . . 83 3.3.6.8 Verifying and Installing System Drivers in Device Manager . . . 84 3.3.6.9 Changing Computer Name (ICC Client) . . . . . . . . . . . . . . . . . . . . 84 3.3.6.10 Connecting Computers to the Network Switch (ICC Client Worksta- tion) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 85 3.3.6.11 Downloading and Applying Windows Defender Updates . . . . . 85 3.3.6.12 Updating Canon Scanner Firmware (ICC Workstation with DRG2140 scanners) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 85 3.3.6.13 Configuring the Canon Scanner Front Panel Settings . . . . . . . . 86 3.3.6.14 Verifying Time Zone, Date, and Time on the ICC Client Workstation (for Standalone ICC) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87 3.3.6.15 Applying Hardening on the ICC Client Workstation . . . . . . . . . 88 3.3.6.16 Post Hardening BIOS (ICC Client Workstation) . . . . . . . . . . . . 88 3.4 Software Installation and Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . 89 3.4.1 EMS Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 89 3.4.1.1 Election Project Configuration in EED . . . . . . . . . . . . . . . . . . . . . . 90 3.4.1.2 Configuring EED for Additional Language Packs . . . . . . . . . . . . . 90 3.4.2 Adjudication Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96 3.4.3 RTR Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 97 ® 3.4.4 ImageCast Central System Configuration . . . . . . . . . . . . . . . . . . . . . 97 3.4.4.1 InterScan HiPro Scanner Hardware Configuration . . . . . . . . . . . 98 ® 3.4.5 ImageCast Evolution Configuration . . . . . . . . . . . . . . . . . . . . . . . . . 99 3.4.5.1 CF0 Card Data Partitioning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99 3.4.5.2 Loading new Languages onto the ICE . . . . . . . . . . . . . . . . . . . . . . 103 ® 3.4.6 ImageCast Precinct 2 Configuration . . . . . . . . . . . . . . . . . . . . . . . . . 104 ® 3.4.7 ImageCast X Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 105 3.5 Acceptance Testing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 105 3.5.1 Election Management System Acceptance Testing . . . . . . . . . . . . . . . 105 ® 3.5.2 ImageCast Evolution Acceptance Testing . . . . . . . . . . . . . . . . . . . . 107 6/18/2024 v Version: 5.19::4 Table of Contents ® 3.5.3 ImageCast Central Acceptance Testing . . . . . . . . . . . . . . . . . . . . . . . 109 ® 3.5.4 ImageCast Precinct 2 Acceptance Testing . . . . . . . . . . . . . . . . . . . . 110 ® 3.5.5 ImageCast X Acceptance Testing . . . . . . . . . . . . . . . . . . . . . . . . . . . . 110 Chapter 4: Election Set-up and Definition . . . . . . 113 4.1 Election Project Database Programming and Configuration . . . . . . . . . . 114 4.2 Tabulator Programming and Configuration . . . . . . . . . . . . . . . . . . . . . . . 114 4.2.1 Performing the Pre-Voting Phase Readiness Test . . . . . . . . . . . . . . . 115 4.2.2 Performing the Voting Phase Readiness Test . . . . . . . . . . . . . . . . . . . 117 ® 4.2.2.1 Voting Phase Readiness Testing ImageCast Evolution . . . . . . . 117 ® 4.2.2.2 Voting Phase Readiness Testing ImageCast Central . . . . . . . . . 118 ® 4.2.2.3 Voting Phase Readiness for ImageCast Precinct 2 . . . . . . . . . . 120 ® 4.2.3 Voting Phase Readiness Testing ImageCast X . . . . . . . . . . . . . . . . . 121 4.2.4 Performing the Election Day Phase Readiness Test . . . . . . . . . . . . . . 122 4.3 System Diagnostics Testing Procedures . . . . . . . . . . . . . . . . . . . . . . . . . . 123 ® 4.3.1 ImageCast Central System Diagnostics Testing Procedures . . . . . . 124 ® 4.3.2 ImageCast Evolution System Diagnostic Testing Procedures . . . . 124 ® 4.3.3 ImageCast Precinct 2 Diagnostic Procedures . . . . . . . . . . . . . . . . . 126 ® 4.3.4 ImageCast X Diagnostic Procedures . . . . . . . . . . . . . . . . . . . . . . . . . 126 4.4 System Proofing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 126 4.5 Logic and Accuracy Testing of System and Components . . . . . . . . . . . . . 146 4.5.1 Pre-Conditions for Performance of Tests . . . . . . . . . . . . . . . . . . . . . . . 147 4.5.1.1 Opening an Election Project . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 147 4.5.1.2 Pre-Testing of the Scanning setting with Official election ballots from the certified ballot printer . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 147 4.5.1.3 Test Decks Required for Logic and Accuracy Testing . . . . . . . . . 148 4.5.1.4 Scanning the USB Media using Windows Defender . . . . . . . . . . . 149 4.5.1.5 Backup of Election Project . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 149 4.5.2 Logic and Accuracy Test Procedures . . . . . . . . . . . . . . . . . . . . . . . . . . 149 ® 4.5.2.1 ImageCast Central Logic & Accuracy Testing Procedure . . . . . 151 ® 4.5.2.2 ImageCast Evolution Logic and Accuracy Test Procedures . . . 153 ® 4.5.2.3 ImageCast Precinct 2 Logic and Accuracy Test Procedures . . . 154 ® 4.5.2.4 ImageCast X Logic and Accuracy Test Procedures . . . . . . . . . . 157 6/18/2024 vi Version: 5.19::4 Table of Contents 4.5.2.5 ImageCast X Vote Simulator . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 158 4.5.2.6 Mobile Ballot Production Logic and Accuracy Test Procedures . 161 4.5.2.7 Adjudication and Post-Election Processing Logic and Accuracy Test Procedures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 164 4.5.3 Logic and Accuracy System Test Acceptance Criteria and Completeness 165 4.5.4 Backing up the Logic and Accuracy Test Results . . . . . . . . . . . . . . . . 165 4.5.4.1 Retention and Documentation of Test Materials . . . . . . . . . . . . . 167 4.5.5 Clearing Logic and Accuracy Test Results . . . . . . . . . . . . . . . . . . . . . . 167 4.5.6 Re-zeroing the ICC . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 167 4.5.7 Re-zeroing the ICE . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 170 4.5.8 Re-zeroing the ICP2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 172 4.5.9 Re-zeroing the ICX . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173 4.6 Election Observer Panel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 174 4.7 Hardware Maintenance and Preparation for Use . . . . . . . . . . . . . . . . . . . 174 ® 4.7.1 ImageCast Evolution Preparation . . . . . . . . . . . . . . . . . . . . . . . . . . . 175 4.7.1.1 Internal Battery Recharging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 175 ® 4.7.2 ImageCast Central Maintenance and Preparation . . . . . . . . . . . . . 175 ® 4.7.3 ImageCast Precinct 2 Preparation . . . . . . . . . . . . . . . . . . . . . . . . . . . 175 4.7.3.1 Internal Battery Recharging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 175 ® 4.7.4 ImageCast X Maintenance and Preparation . . . . . . . . . . . . . . . . . . 177 4.7.4.1 BMD printer cartridge removal/replacement/storage . . . . . . . . . 178 4.7.4.2 ICX Internal Battery Recharging . . . . . . . . . . . . . . . . . . . . . . . . . . 178 4.8 Physical Security of Equipment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178 Chapter 5: Early Voting Procedures . . . . . . . . . . . 179 ® 5.1 ImageCast Evolution . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179 ® 5.2 ImageCast Precinct 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 181 ® 5.3 ImageCast X . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 182 Chapter 6: Polling Place Procedures . . . . . . . . . . . 183 6.1 Precinct Supplies, Delivery and Inspection . . . . . . . . . . . . . . . . . . . . . . . . 183 6.1.1 Precinct Supplies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 183 ® 6.1.2 ImageCast Evolution and Related Equipment . . . . . . . . . . . . . . . . . 184 6/18/2024 vii Version: 5.19::4 Table of Contents 6.1.2.1 Delivery of Equipment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 186 6.1.2.2 Proper Handling and Moving Procedures . . . . . . . . . . . . . . . . . . . 187 ® 6.1.3 ImageCast Precinct 2 and Related Equipment . . . . . . . . . . . . . . . . . 187 ® 6.1.4 ImageCast X and Related Equipment . . . . . . . . . . . . . . . . . . . . . . . . 189 6.2 Inspection and Polling Place Setup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 190 6.2.1 ICE Equipment Setup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 191 6.2.1.1 Opening the Monitor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 191 6.2.1.2 Election Memory Cards . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 191 6.2.1.3 Attaching the Audio Tactile Interface . . . . . . . . . . . . . . . . . . . . . . 191 6.2.1.4 Setting up the Voting Booth . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 192 6.2.2 ICP2 Equipment Setup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 193 6.2.2.1 Setting up the Tabulator on the Ballot Box . . . . . . . . . . . . . . . . . . 193 6.2.2.2 Replacing the Thermal Printer Paper Roll . . . . . . . . . . . . . . . . . . 195 6.2.2.3 Powering Up the Tabulator . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 195 6.2.2.4 Applying Security Seals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 196 6.2.2.5 Sealing Memory Card Access Ports . . . . . . . . . . . . . . . . . . . . . . . . 197 6.2.2.6 Sealing the Thermal Report Printer Door . . . . . . . . . . . . . . . . . . . 197 6.2.2.7 Sealing the Modem Port . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 198 6.2.2.8 Ballot Review . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 198 6.2.3 ICX Equipment Setup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 200 6.2.3.1 Unpacking the Equipment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 200 6.2.3.2 Setting up the Equipment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 200 6.2.3.3 Voting Booth Set Up . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 201 6.3 Opening the Polls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 201 6.3.1 Opening the Polls on the ICX . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 201 6.3.2 Opening the Polls on the ICE . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 204 6.3.3 Opening the Polls on ICP2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 213 6.3.3.1 Viewing Tabulator Info on the LCD Screen . . . . . . . . . . . . . . . . . . 216 6.4 Polling Place Procedures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 219 ® 6.4.1 ImageCast Evolution . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 220 6.4.1.1 Standard Voting Session . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 220 6.4.1.2 Write-In (Ballot Review Disabled) . . . . . . . . . . . . . . . . . . . . . . . . 224 6/18/2024 viii Version: 5.19::4 Table of Contents 6.4.1.3 Overvote (Ballot Review Enabled) . . . . . . . . . . . . . . . . . . . . . . . . 224 6.4.1.4 Overvote (Ballot Review Disabled) . . . . . . . . . . . . . . . . . . . . . . . . 225 6.4.1.5 Undervotes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 226 6.4.1.6 Ambiguous Marks (Ballot Review Enabled) . . . . . . . . . . . . . . . . 226 6.4.1.7 Ambiguous Marks (Ballot Review Disabled) . . . . . . . . . . . . . . . . . 227 6.4.1.8 Correctly Marked Ballot with No Write Ins . . . . . . . . . . . . . . . . . . 227 ® 6.4.1.9 Operating the ImageCast Evolution on Battery . . . . . . . . . . . . 228 6.4.1.10 Changing the Printer Paper Tape . . . . . . . . . . . . . . . . . . . . . . . . 228 6.4.1.11 Thermal Paper Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 229 6.4.2 Standard Voting Session On ICP2 . . . . . . . . . . . . . . . . . . . . . . . . . . . 230 6.4.2.1 Handling Non-typical Voting Scenarios . . . . . . . . . . . . . . . . . . . 233 6.4.2.2 Second Chance Voting Scenarios . . . . . . . . . . . . . . . . . . . . . . . . . 233 6.4.2.3 Overvoted Ballots . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 235 6.4.2.4 RCV Voting Scenarios . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 238 6.4.3 Standard Voting on ICX . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 240 6.4.3.1 Voting Interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 241 ® 6.4.3.2 ImageCast X Early Voting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 243 ® 6.4.3.3 ImageCast X Manual Session Activation . . . . . . . . . . . . . . . . . 243 6.5 Accessible Voting Procedures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 243 6.5.1 Accessible Voting on ICE . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 243 6.5.1.1 Accessible Voting Session . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 243 6.5.2 Accessible Voting on ICX . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 260 6.6 Provisional Voters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 266 6.6.1 Provisional Voting on ICE . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 266 6.6.1.1 Provisional Voting Using the Accessible Voting Features of the Im- ® ageCast Evolution . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 267 6.6.1.2 In Precinct . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 268 6.6.1.3 Out of Precinct . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 268 6.6.2 Provisional Voting on ICX . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 268 6.7 Closing the Polls and Vote Reporting . . . . . . . . . . . . . . . . . . . . . . . . . . . . 269 6.7.1 Closing the Polls on ICE . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 269 6.7.2 Closing the polls on ICP2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 275 6.7.2.1 Powering Down the Tabulator . . . . . . . . . . . . . . . . . . . . . . . . . . . 282 6/18/2024 ix Version: 5.19::4 Table of Contents 6.7.3 Closing the Polls on ICX . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 284 6.8 Securing Audit Logs and Backup Records . . . . . . . . . . . . . . . . . . . . . . . . 284 6.9 Troubleshooting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 285 ® 6.9.1 Operating the ImageCast Precinct 2 on Battery . . . . . . . . . . . . . . . 285 6.9.2 Operating the ICX on Battery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 285 ® 6.9.3 Operating the ImageCast Evolution on Battery . . . . . . . . . . . . . . . 285 Chapter 7: Absentee, Mail, and Central Count Procedures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 288 7.1 Preparing Absentee/Vote by Mail Ballots for Tally . . . . . . . . . . . . . . . . . 288 ® 7.2 Setting up the ImageCast Central Workstation and Scanner . . . . . . . 288 ® 7.3 Backing Up ImageCast Central Files From Prior Elections . . . . . . . . 289 7.3.1 Copying Tabulator Election Files to the ICC Workstation . . . . . . . . . 291 ® 7.4 Loading an Election to the ImageCast Central System . . . . . . . . . . . . 293 7.5 Configuring the Secondary or Server Path for Saving Results . . . . . . . 298 7.6 Configuring Scan Options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 301 7.7 Accessing Supervisor Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 306 7.7.1 Canon and HiPro Scanner Imprinters . . . . . . . . . . . . . . . . . . . . . . . . 307 7.7.1.1 Canon DR-G1130 and DR-G2140 Scanner Imprinters . . . . . . . . 308 7.7.1.2 InoTec HiPro Scanner Imprinters . . . . . . . . . . . . . . . . . . . . . . . . . 310 7.8 Producing a Zero Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 312 7.9 Scanning Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 318 7.9.1 Scanning and Accepting Batches . . . . . . . . . . . . . . . . . . . . . . . . . . . . 320 7.9.2 Scanning and Discarding Batches . . . . . . . . . . . . . . . . . . . . . . . . . . . 322 7.9.3 Spoiling a Batch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 322 7.9.3.1 Spoiling Batches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 323 7.9.3.2 Deleting Batches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 325 ® 7.9.4 Producing Reports from the ImageCast Central System and Closing the Tabulator . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 328 7.9.4.1 Generating a Status Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 328 7.9.4.2 Closing the Tabulator . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 331 7.9.4.3 Generating a Results Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . 333 Chapter 8: Semi-Official Canvass Tabulation and 6/18/2024 x Version: 5.19::4 Table of Contents Reporting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 336 8.1 System Start-up and Pre-tabulation Report Procedures . . . . . . . . . . . . 336 8.1.1 Start EMS RTR . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 336 8.1.2 Open Project . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 337 8.1.3 Run Zero Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 338 8.2 Processing Vote Reports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 339 8.2.1 Loading Results from Removable Media Management . . . . . . . . . . 339 8.2.2 Load Results from Directory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 344 8.2.3 Automatic Result Loading . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 344 8.2.3.1 Automatic Images Loading . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 346 8.2.4 Validate and Publish Results . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 346 8.2.5 Election Night Summary Report - Election Day Report . . . . . . . . . 346 8.2.6 Central Tabulation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 347 ® 8.2.6.1 Early Vote ImageCast Evolution and ImageCast® Precinct 2 348 8.2.7 Precinct Tabulation (ICE and ICP2) . . . . . . . . . . . . . . . . . . . . . . . . . 348 ® 8.2.8 Precinct Tabulation (ImageCast X) . . . . . . . . . . . . . . . . . . . . . . . . . 350 8.3 Integration with County Systems and Calvoter/VoteCal . . . . . . . . . . . . 350 8.3.1 Load Mappings and Templates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 351 8.3.2 Verify and edit contest mappings . . . . . . . . . . . . . . . . . . . . . . . . . . . . 354 8.3.3 Verify and edit district mappings . . . . . . . . . . . . . . . . . . . . . . . . . . . . 356 8.3.4 Create Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 357 Chapter 9: Adjudication . . . . . . . . . . . . . . . . . . . . 360 9.1 Adjudication Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 360 9.1.1 Adjudication Workflow . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 360 9.2 Create Adjudication Administrators and Adjudication Users . . . . . . . . 360 9.2.1 Accessing the Users Screen/Menu Item . . . . . . . . . . . . . . . . . . . . . . 360 9.2.2 Creating New Users . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 362 9.3 Assigning Elections to Users . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 364 9.3.1 Assigning Users to an Election from the Users Screen . . . . . . . . . . 364 9.3.2 Assigning Users to an Election from the Election Event Screen . . . 365 9.4 Creating Adjudication Profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 367 9.5 Starting an Adjudication Session . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 375 6/18/2024 xi Version: 5.19::4 Table of Contents 9.6 Using the Adjudication Application . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 383 9.6.1 Entering into Ballot Adjudication as an Administrator . . . . . . . . . . 384 9.6.2 Entering into Ballot Adjudication as an Adjudicator . . . . . . . . . . . . 385 9.7 Understanding the Ballot Review Window . . . . . . . . . . . . . . . . . . . . . . . 387 9.7.1 Ballot Information Panel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 387 9.7.2 History Panel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 388 9.7.3 Contests Panel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 389 9.7.4 Quarantine Panel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 391 9.7.5 History Panel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 392 9.7.6 Ballot Navigation Options: Zooming In and Out/Fit to Page . . . . . 394 9.7.7 Ballot Navigation Options: Overlays and Views . . . . . . . . . . . . . . . . 396 9.7.8 Ballot Navigation Options: Collapsing the Contest, Quarantine and History Panels . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 402 9.8 Adjudicating Ballots . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 403 9.8.1 Understanding Ballot Overlays . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 403 9.8.2 Toggling the Vote Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 405 9.8.3 Resolving Write-ins . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 407 9.9 Batch Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 411 9.9.1 Submitting Batches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 413 9.9.2 Sending Batches Back to Review or Adjudication . . . . . . . . . . . . . . . 414 Chapter 10: Official Canvass and Post-Election Procedures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 416 10.1 Election Observer Panel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 417 10.2 Canvassing Precinct Returns . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 417 10.3 Canvassing Absentee Ballots . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 419 10.4 Canvassing Provisional Ballots . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 421 10.5 Canvassing Write-in Votes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 421 10.6 1% Manual Recount Procedures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 422 10.7 Post-Election Logic and Accuracy Testing . . . . . . . . . . . . . . . . . . . . . . . 423 10.8 Final Reporting of Official Canvass . . . . . . . . . . . . . . . . . . . . . . . . . . . . 423 10.9 Backup and Retention of Election Material . . . . . . . . . . . . . . . . . . . . . 424 10.9.1 General Procedures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 424 6/18/2024 xii Version: 5.19::4 Table of Contents 10.9.2 Security of Materials Following Ballot Tally . . . . . . . . . . . . . . . . . . 424 Chapter 11: Recount Procedures . . . . . . . . . . . . . 425 11.1 Request for a Recount . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 425 11.2 Conducting an Electronic Recount . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 425 11.2.1 Creating Recount Election Projects . . . . . . . . . . . . . . . . . . . . . . . . . . 425 11.2.2 Recounting the Ballots . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 426 11.2.3 Consolidating Recounted Results . . . . . . . . . . . . . . . . . . . . . . . . . . . 426 Chapter 12: EMS Administrator's Role in Managing System Security and Integrity . . . . . . . . . . . . . . . 427 12.1 Physical Security of System and Components . . . . . . . . . . . . . . . . . . . . 427 12.1.1 Essential and Non-Essential Services and Ports . . . . . . . . . . . . . . . 429 12.1.2 Anti-Virus Protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 429 12.1.3 Procedures for Verifying, Checking, and Installing Essential Updates and Changes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 430 12.1.4 Audit Records for Changes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 430 12.2 Administrative Control of the Backup and Restore of an Election Project 430 12.2.1 Backing Up an Election Project . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 430 12.2.2 Restoring an Election Project . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 432 12.2.3 Encrypting an Election Project . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 433 12.2.4 Importing an Encryption Certificate . . . . . . . . . . . . . . . . . . . . . . . . 434 12.2.5 Exporting Encryption Certificates . . . . . . . . . . . . . . . . . . . . . . . . . . 436 12.2.6 Setting up Project for Additional Audio Languages . . . . . . . . . . . . 438 12.2.7 Creation of RTR User in Election Event Designer . . . . . . . . . . . . . 439 12.2.8 Initializing Reporting Services . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 439 12.3 Disabling and Enabling Adjudication in EMS RTR . . . . . . . . . . . . . . . 440 12.4 Purging Election Results . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 440 12.4.1 Purging Election Results from RTR . . . . . . . . . . . . . . . . . . . . . . . . . 440 12.5 Security Procedures for Central Processing . . . . . . . . . . . . . . . . . . . . . . 440 12.6 Security Procedures for Polling Places . . . . . . . . . . . . . . . . . . . . . . . . . . . 441 12.6.1 Polling Place Physical Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 441 12.7 Audit Trails . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 441 6/18/2024 xiii Version: 5.19::4 Table of Contents ® 12.7.1 ImageCast Evolution Audit Trail Files . . . . . . . . . . . . . . . . . . . . . . . 441 ® 12.7.1.1 ImageCast Evolution Audit Log File . . . . . . . . . . . . . . . . . . . . . 442 ® 12.7.2 ImageCast Precinct 2 Audit Trail Files . . . . . . . . . . . . . . . . . . . . . 442 ® 12.7.2.1 ImageCast Precinct 2 Audit Log File . . . . . . . . . . . . . . . . . . . . 442 ® 12.7.3 ImageCast Central Audit Trail Files . . . . . . . . . . . . . . . . . . . . . . . 442 ® 12.7.3.1 ImageCast Central Audit Log File . . . . . . . . . . . . . . . . . . . . . . 442 12.7.3.2 Audit Mark Images . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 443 12.7.3.3 Audit Trail Files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 443 ® 12.7.4 ImageCast X Audit Trails . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 444 12.7.5 EMS Audit Trail File . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 444 12.7.5.1 EMS Audit Log . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 444 12.7.5.2 Unauthorized Access to the Access Control Capabilities of the Sys- tem . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 445 12.7.5.3 Reports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 445 12.7.5.4 Create, Preview and Delete Reports . . . . . . . . . . . . . . . . . . . . . . 445 12.7.5.5 How to Download Reports from the NAS Server . . . . . . . . . . . 446 12.7.5.6 How to View System Level Logs . . . . . . . . . . . . . . . . . . . . . . . . . 447 12.7.5.7 Results Auditing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 447 ® 12.7.5.8 ImageCast Adjudication Audit Trail . . . . . . . . . . . . . . . . . . . . 447 12.7.5.9 Lookup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 448 12.7.5.10 EMS Data Center Physical Security . . . . . . . . . . . . . . . . . . . . . 449 12.7.5.11 Operational and Maintenance Procedures . . . . . . . . . . . . . . . . 449 Chapter 13: Biennial Hardware Certification and Notification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 451 13.1 Notification of Equipment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 451 Appendix A: ImageCast® Central 2 Machine Behavior Settings . . . . . . . . . . . . . . . . . . . . . . . . . . 452 Appendix B: ImageCast® Evolution and ImageCast® Precinct 2 Machine Behavioral Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 453 B.1 Polling Place Tabulators . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 454 B.2 Early Voting Tabulators . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 454 6/18/2024 xiv Version: 5.19::4 Table of Contents Appendix C: ImageCast® X Configuration Files . 455 C.1 Election Day ICX Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 456 C.2 Early Vote ICX Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 456 Appendix D: Election Event Designer Supplemental Setup Instructions . . . . . . . . . . . . 457 D.1 Jurisdictions Serviced by Dominion Voting . . . . . . . . . . . . . . . . . . . . . . . 457 D.2 Jurisdictions Programming Their Own Elections . . . . . . . . . . . . . . . . . . 457 D.2.1 Creating Election Project . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 457 D.2.1.1 Set Ballot Consolidation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 457 D.2.1.2 Setting Header Watermark . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 458 ® D.2.1.3 Maximum Number of Precincts to Associate to an ImageCast Evo- ® lution or ImageCast Precinct 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 458 D.2.1.4 Defining Counting Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 459 D.2.1.5 Defining Tabulators . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 459 D.2.2 Creating Tabulators in the Ready for Elections Phase . . . . . . . . . . 460 D.2.3 Fonts, Languages and Ligatures . . . . . . . . . . . . . . . . . . . . . . . . . . . . 460 D.2.4 Audio Studio Instructions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 461 D.2.5 Creating Additional Audio Files for an Election Project . . . . . . . . . . 461 D.2.6 Tabulator Threshold Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 461 D.2.7 Programming of Election Files and Security Devices . . . . . . . . . . . 462 D.2.7.1 Programming of CF/SD Cards . . . . . . . . . . . . . . . . . . . . . . . . . . . 462 D.2.7.2 Programming of iButton Security Key . . . . . . . . . . . . . . . . . . . . 462 D.2.7.3 Programming Technician Smart Cards . . . . . . . . . . . . . . . . . . . . 463 D.2.7.4 Program USB flash drive for ImageCast X Devices . . . . . . . . . . 464 D.2.8 Programming of poll worker Smart Card . . . . . . . . . . . . . . . . . . . . . 465 D.3 Exporting of Voter Activation Codes from EED . . . . . . . . . . . . . . . . . . . 466 ® D.4 Importing Activation Codes to the ImageCast Voter Activation Application . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 470 D.5 Programming of Voter Activation Smart Card . . . . . . . . . . . . . . . . . . . . . 471 D.6 Smart Card Security Recommendations . . . . . . . . . . . . . . . . . . . . . . . . . 478 6/18/2024 xv Version: 5.19::4 Table of Contents Appendix E: InterScan HiPro Scanner Handling Checklist . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 480 Appendix F: Troubleshooting and Problem Resolution . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 481 ® F.1 ImageCast Evolution Troubleshooting . . . . . . . . . . . . . . . . . . . . . . . . . . 481 F.1.1 Replacing a Machine . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 481 F.1.2 Paper Jams . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 482 F.1.2.1 Paper Jam in Scanner Path . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 482 F.1.3 Power Failures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 483 F.1.3.1 Faulty Main's Power Source . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 483 F.1.3.2 Faulty or Disconnected Power Adapter . . . . . . . . . . . . . . . . . . . . 483 F.1.4 Thermal Printer . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 483 F.1.4.1 No Print on Thermal Paper or Printer Fails to Print . . . . . . . . . 484 F.1.4.2 Thermal Printer Prints Invalid Characters . . . . . . . . . . . . . . . . . 484 F.1.5 Touchscreen Failures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 484 ® F.2 ImageCast Central Troubleshooting . . . . . . . . . . . . . . . . . . . . . . . . . . . 485 F.2.1 Ballot Scanning Errors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 485 F.2.1.1 Ambiguous Errors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 485 F.2.1.2 InterScan HiPro Scanning Errors . . . . . . . . . . . . . . . . . . . . . . . . . 485 F.3 EMS Troubleshooting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 486 F.3.1 Submission and Publishing of Batches . . . . . . . . . . . . . . . . . . . . . . . 488 ® F.4 ImageCast X Troubleshooting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 488 F.4.1 Power failure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 488 F.4.2 Printer paper jam . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 488 F.4.2.1 Low Toner . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 488 F.4.3 Replacing BMD printer . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 489 F.4.4 Replacing ICX device . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 489 F.4.5 Errors During Printing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 491 F.5 ImageCast® Precinct 2 Troubleshooting . . . . . . . . . . . . . . . . . . . . . . . . . 491 F.5.1 Power-up/Set-up Issues . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 491 F.5.1.1 Tabulator Does not Power-up . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 491 F.5.1.2 Security Key (iButton) Error . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 492 6/18/2024 xvi Version: 5.19::4 Table of Contents F.5.2 Report Printer (Thermal Printer) Issues . . . . . . . . . . . . . . . . . . . . . . 492 F.5.2.1 Thermal Tape Printer Error - Loose Pressure Roller . . . . . . . . . 492 F.5.2.2 Thermal Tape Printer Error - No Paper Loaded . . . . . . . . . . . . 492 F.5.2.3 Report Tape not Printing on Thermal Paper . . . . . . . . . . . . . . . 493 F.5.3 Scanner (Tabulator) Issues . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 493 F.5.3.1 Scanner (Tabulator) Does not Accept Ballots . . . . . . . . . . . . . . . 493 F.5.4 Tabulator Paper Jam . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 493 F.5.4.1 Input Slot Paper Jam . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 493 F.5.4.2 Exit Slot Paper Jam . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 494 F.5.4.3 On Startup Paper Jam . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 496 F.6 Reporting Troubleshooting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 497 F.6.1 Batch Selection List Does Not Refresh Immediately . . . . . . . . . . . . 497 Appendix G: Threat Register . . . . . . . . . . . . . . . . 498 Appendix H: Physical Security of Democracy Suite® System and Components . . . . . . . . . . . . . . 506 H.1 Re-Zero Results Using the Advanced Admin Option . . . . . . . . . . . . . . 506 H.2 Physical Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 508 H.3 Plastic Ballot Box Physical Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . 509 ® H.4 ImageCast Evolution Physical Security . . . . . . . . . . . . . . . . . . . . . . . . . 513 ® H.5 ImageCast Central Physical Security . . . . . . . . . . . . . . . . . . . . . . . . . . . 515 ® H.6 ImageCast Precinct 2 Physical Security . . . . . . . . . . . . . . . . . . . . . . . . . 516 H.6.1 Sealing Administrator and Poll Worker Memory Card Access Ports . . . 517 H.6.2 Sealing the Thermal Report Printer Door . . . . . . . . . . . . . . . . . . . . . 518 H.6.3 Sealing the Modem Port . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 519 H.7 Re-zeroing the ICP2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 519 H.8 EMS Server and Workstation Physical Security . . . . . . . . . . . . . . . . . . . 519 ® H.9 ImageCast X Physical Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 523 ® H.10 Reset the Number of Printed Ballots on ImageCast X . . . . . . . . . . . 526 ® H.11 Clear All Election Data on ImageCast X . . . . . . . . . . . . . . . . . . . . . . . 526 Appendix I: Permanent Printed Reports . . . . . . . 527 I.1 Diagnostics Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 527 6/18/2024 xvii Version: 5.19::4 Table of Contents I.2 Zero Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 527 I.3 Interrupt Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 527 I.4 Results Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 528 I.5 Status Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 528 Appendix J: Certified Firmware . . . . . . . . . . . . . 530 J.1 Democracy Suite EMS Certified Versions . . . . . . . . . . . . . . . . . . . . . . . . 530 J.2 ImageCast Tabulator & BMD Certified Firmware Versions . . . . . . . . . 530 Appendix K: BIOS Settings Quick Reference . . . 532 K.1 EMS Standard Server (PowerEdge R660) . . . . . . . . . . . . . . . . . . . . . . . . 532 K.2 BIOS EMS Client/ADJ Client (Precision 3460) . . . . . . . . . . . . . . . . . . . 533 K.3 ICC (OptiPlex 7440 AIO/5270 AIO), ICVA (Latitude 3410/3400), RTM (Latitude 3400) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 534 K.4 Configure BIOS (Admin) password (Windows 11 Computers) . . . . . . . . 535 K.5 Disable boot from USB (Windows 11 Computers) . . . . . . . . . . . . . . . . . . 535 Appendix L: Bitlocker Encryption . . . . . . . . . . . . 536 L.1 Enabling BitLocker to EMS Client and Express Systems . . . . . . . . . . . . 536 L.2 Enabling BitLocker Using Trusted Platform Module (TPM) to Client and Express Systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 536 Revision History . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 538 List of Figures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 539 List of Tables . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 551 Index . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 553 6/18/2024 xviii Version: 5.19::4 Chapter 1 - Introduction CHAPTER 1: INTRODUCTION ® This document describes Dominion Voting Systems’ Democracy Suite 5.19 platform as outlined in the Voting System Use Procedures for California Template. 1.1 System Description and Components This section defines the system description and components as specified by section 1.1 of the System Use Procedures for California Template. 1.1.1 ImageCast® Evolution (ICE) ® Figure 1-1: ImageCast Evolution ® ImageCast Evolution Ballot Counter is a precinct-based optical scan ballot ® tabulator that is used in conjunction with ImageCast -compatible ballot boxes. The system is designed to scan marked paper ballots, interpret voter marks on the paper ballot, and safely store and tabulate each vote made on the ballot. As well, ® the ImageCast Evolution supports enhanced accessibility voting through optional accessories that are connected to the unit and via the 18.5" LCD touchscreen. 6/18/2024 1 Version: 5.19::4 Chapter 1 - Introduction Once an accessible voting session has been activated, the Voter inserts a blank ballot and makes their selections using the Audio Tactile Interface (ATI), Paddles, or Sip 'n' Puff devices. When the accessible voting session has been completed, the ® ImageCast Evolution will mark the ballot according to the selections made in a manner that renders it indistinguishable from normally printed and hand-marked ® ballots. This ballot is then scanned back into the ImageCast Evolution for ® tabulation, which is then deposited into the secured ImageCast ballot box. ® The ImageCast Evolution's major system elements are listed in the following table. ICE's Major System Elements Linux Operating System MPC8347E PowerPC Processor-based Motherboard Internal type II Compact Flash memory cards Two optical imaging scanners Backlit LCD touch panel Internal thermal printer Internal inkjet printer iButton administrative security key interface Paper feed mechanism Ballot diverter Power supply module Battery pack Ballot box Packaging Table 1-1: ICE’s Major System Elements 6/18/2024 2 Version: 5.19::4 Chapter 1 - Introduction 1.1.2 ImageCast® Central (ICC) ® Figure 1-2: 5.19 ImageCast Central (ICC) G2140 ® The ImageCast Central system is a combination of a commercial off-the-shelf high-speed scanner manufactured, coupled with a ballot processing application which runs on a Dell workstation. The system is designed for use in a central scanning location, to process vote by mail ballots, or to run and process an entire election. 6/18/2024 3 Version: 5.19::4 Chapter 1 - Introduction ® The ImageCast Central's major system elements are listed in Table1-2. ICC's Major System Elements Windows 11, version 22H2 x64 (updated May 2023) 64-bit operating system All-In-One Computer: • IntelCore i7 processor (Quad Core, 8 MB, 8 T, 3.4 GHz, 65 W) • 8 GB RAM • 500 GB hard disk • CDROM/DVD ROM reader • Ethernet port for uploading results files • Dedicated USB port for: • 1-wire iButton Reader • Compact Flash card reader • Scanner Tower: • Intel Core i7-8700T (6 Cores/12MB/12T/up to 4.0GHz/35W) • 16 GB • 256 GB SSD • CDROM/DVD ROM reader • Ethernet port for uploading results files • Dedicated USB port for: • 1-wire iButton Reader • Compact Flash card reader • Scanner Touch screen monitor Scanner: • Canon DR-G1130 • Canon DR-G2140 • InterScan HiPro Table 1-2: ICC's Major System Elements 6/18/2024 4 Version: 5.19::4 Chapter 1 - Introduction 1.1.3 ImageCast® Precinct 2 ® Figure 1-3: ImageCast Precinct 2 ® The ImageCast Precinct 2 (ICP2) is a precinct optical scan ballot tabulator designed to scan marked paper ballots, interpret voter marks on the paper ballot, communicate these interpretations back to the voter, and upon acceptance by the voter, deposit the ballots into the secure ballot box. The ICP2’s major system elements are listed in the following table. ICP2’s Major System Elements Linux Operating System NXP i.MX6 Dual Core Processor-based Motherboard Internal SD memory cards Two optical imaging scanners 5.7” LCD touch panel Internal thermal printer iButton administrative security key interface Paper feed mechanism Ballot diverter Table 1-3: ICP2’s Major System Elements 6/18/2024 5 Version: 5.19::4 Chapter 1 - Introduction ICP2’s Major System Elements Battery pack Ballot box Packaging Table 1-3: ICP2’s Major System Elements (Continued) 1.1.4 Election Management System (EMS) Figure 1-4: EMS Workstation and EMS Server ® The Democracy Suite Election Management System (EMS) is a set of applications used for defining and managing elections. EMS runs on a Dell Precision workstation and Dell server, see Figure1-4. The complete EMS software platform consists of client and server applications as follows: Applications: ® • Democracy Suite EMS Audio Studio: A supplementary application used to record audio files for an election project. As such, it is used during the pre- voting phase of the election cycle. ® • Democracy Suite EMS Election Data Translator: A supplementary client application used to import, edit, and export template election project data into, and out of, Election Event Designer. ® • Democracy Suite EMS File System Service: A standalone service that runs on client machines for the partitioning of Compact Flash cards. ® • Democracy Suite EMS Data Center Manager: A system level configuration application used in the EMS back-end data center configuration. 6/18/2024 6 Version: 5.19::4 Chapter 1 - Introduction ® • Democracy Suite EMS Application: A server based installation setup of a browser based application delivered over the local EMS Network through a browser interface on Adjudication client workstations that allow reviewing and adjudicating vote results from ImageCast Tabulators. ® • Democracy Suite EMS Election Event Designer: Provides election definition functionality and represents a main pre-voting phase end-user application. ® • Democracy Suite EMS Results Tally & Reporting: Provides election results acquisition, validation, tabulation, reporting, and publishing capabilities, and represents a main post-voting phase end-user application. ® ® • Democracy Suite ImageCast Adjudication: A set of server-side services ® and a client-side application that provide adjudication of ImageCast Central ballot images. Data Repositories: ® • Democracy Suite EMS Network Attached Storage (NAS) Server: A server- side file repository of the election project file-based artifacts, such as ballots, audio files, reports, log files, election files, etc. ® • Democracy Suite EMS Database Server: A server-side RDBMS repository of the election project database that holds all pre-voting and post-voting election project data. 1.1.5 ImageCast® X (ICX) ® Figure 1-5: ImageCast X 6/18/2024 7 Version: 5.19::4 Chapter 1 - Introduction ® ImageCast X is a ballot marking device, which includes a commercial off-the- shelf Android device and compatible printer, see Figure1-5. The Android device is running a BMD application in KIOSK mode.The system is designed for use on a polling location, to produce marked ballots that can be scanned using an ICC, ICE or ICP2 tabulator. ® The ImageCast X 's major system elements are listed in Table1-4. ICX's Major System Elements Android 8.1 Intel(R)Atom(TM)CPU Z3735F @ 1.33 GHz 2 GB RAM 32 GB solid state disk ACOS Smart Card Reader Printer: • HP M402dn • HP M402dne • HP M404dn • HP 4001dn Dedicated USB port for: • USB media device with election files • Smart Card Reader • Printer • AVS device Battery and UPS for standalone operation Table 1-4: ICX's Major System Elements 6/18/2024 8 Version: 5.19::4 Chapter 1 - Introduction 1.2 Equipment Cleaning/Disinfecting Guidelines Equipment can be wiped down with a clear Isopropyl Alcohol/water-based solution, using a lint-free wipe. To clean and sanitize, it is best to use a mixture of 70% alcohol and 30% water or stronger mix solution. Use at least 70% alcohol. THE USE OF ALCOHOL OR OTHER CLEANING/DISINFECTING AGENTS MAY RESULT IN PERSONAL INJURY AND PROPERTY DAMAGE. To avoid potential hazards, follow the recommended Safety Precautions and cleaning instructions: • Do NOT use solutions that contain ammonia as well as acidic, alkali, or other caustic chemicals. • Do NOT use vinegar-based solutions. • Do NOT use coarse cloths or paper towels. ® • Do NOT spray cleaning/disinfecting agents directly on the ImageCast Central 2 tabulator or ICX Touchscreen. • To avoid spotting, make certain that equipment screens are wiped dry. • Do not leave puddles. • Do not wipe or wet paper ballots. ® For ImageCast® X Touchscreens, ImageCast Precinct 2 or ImageCast® Evolution systems, thoroughly clean all units in every polling place each morning before powering them on. Clean the units again in the evening after they have been powered off. • Follow the CAUTION information in the enclosed instructions to prevent damage to your voting system touchscreens and tabulators. Cleaning the units while they are powered is acceptable, however moist wipes may alter the touch sensitivity of screens until the moisture is removed. Additionally, some screen buttons may be inadvertently activated during wipe down. • Regular alcohol wipes can be used for cleaning activation cards and nonporous privacy sleeves. NOTE: These products are intended solely for cleaning the exterior of the tabulators. Do not apply to the interior components of the system. For ImageCast tabulators: • Mix of isopropyl alcohol and water solution with a ratio of at least 70% 50% alcohol, up to 100% isopropyl alcohol. 6/18/2024 9 Version: 5.19::4 Chapter 1 - Introduction Recommended Disinfecting/Cleaning Agents: • 3MTM Scotch-Brite® Electronics Cleaning Cloth • TECHSPRAY® 2368-2 LCD and Plasma Screen Cleaning Wipes Disinfectant • KIMTECH® One-Step Disinfectant Wipes 1.2.1 Instructions for Cleaning and Disinfecting an ImageCast® Tabulator or ICX Touchscreen General Cleaning/Disinfecting Instructions: 1. Power-off the unit and all attached peripherals. 2. Spray a small amount of cleaning/disinfecting agent onto the cloth. (Not directly on the unit) 3. Wipe the touchscreen, Cast/Return buttons, and any other external surfaces that are accessible to user. 4. Wipe down other handheld accessories such as Smart Cards, ATI, headset etc. 5. Use a dry cloth to wipe any excess moisture. 6. Power the unit back on, if required. Cleaning/Disinfecting Instructions While in Use: 1. Ensure that unit is in the idle mode. 2. Spray a small amount of cleaning/disinfecting agent onto the cloth (do not apply the cleaning agent directly on the unit). 3. Wipe the Touch screen, Cast/Return buttons, and any other external surfaces that are accessible to user. 4. Wipe down other handheld accessories such as Smart Cards, ATI, headset etc. 5. Use a dry cloth to wipe any excess moisture. Other Recommended Methods for keeping the System Clean include: • Wear Latex Gloves (the PCap/resistive touchscreens work well with latex gloves). • Consider using a PCap Stylus (Either disposable or disinfect the stylus after each use). • Be sure to wipe down the Smart Card before handing it to the user. 6/18/2024 10 Version: 5.19::4 Chapter 1 - Introduction 1.3 Terms and Definitions • Absentee Ballot: A ballot cast by a voter other than in-person on election day. Some jurisdictions use the term synonymous with mailed ballots while other jurisdictions use the term synonymous with early voting. • Accessible Voting Session (AVS): A method of voting for voters who are unable to easily mark their paper ballot. Audio, visual, and tactile interfaces are used in any voter-preferred combination to navigate and mark a ballot. • Accuracy Test: Consists of tabulating a known number of ballots, with a known pattern of voted positions, into the Election Management System to ensure its accuracy. This test is used to verify that the election project set-up, the production of the ballots, and the vote tallying hardware are operating correctly. • Adjudication: The process of examining voted ballots to determine, and, in the judicial sense, adjudicate voter intent. The application used for this ® purpose is primarily ImageCast Adjudication. • Application Server (APPS): A server-side application responsible for executing long-running processes such as rendering ballots, generating audio and election files, etc. • Audio Studio (AS): A supplementary pre-voting user application used to review, record and import audio files for an election project. • Audio Tactile Interface (ATI): A hand-held controller that allows a voter, who is unable, to mark their paper ballot, to navigate and make selections to a ballot that is presented in audio and visual form during an Accessible Voting Session. • Audit Trail: Information recorded during election activities to reconstruct steps followed or to later verify actions taken with respect to election procedures and voting systems. • Backup: Equipment and procedures available in the event of failure of the voting system. • Ballot: The official presentation of all of the contests to be decided in a particular election. Either in paper or electronic format, the mechanism for voters to show their voter preferences. • Ballot Box: A secure ballot storage container where tabulated ballots are ® automatically deposited once scanned through an ImageCast tabulator. • Ballot Counter: Feature in a voting device that counts the votes cast in an election. This can also refer to a person who counts vote by hand. • Ballot Definition: Information that describes to a voting machine the content and appearance of the ballots to be used in an election. 6/18/2024 11 Version: 5.19::4 Chapter 1 - Introduction • Ballot Definition Subsystem: Includes all hardware, software, and manual procedures required to accomplish the following: • Administrative Activities • Candidate and Contest Definition • Voter Registration Databases Management • Ballot Generation • Election Programming • Ballot Printing/Display • Ballot Validation • Ballot Image: Electronically produced record of all votes cast by a single voter. Also, can mean a digital image of a voted ballot captured by a voting system or ballot tabulation device. • Ballot Layout: The ballot configuration unique to each precinct or split precinct that encompasses all candidates, including any rotation of candidate names, and ballot measures. The contents may be rendered using various methods of presentation (visual or audio), language or graphics. • Ballot Style: A ballot with a specific set of contests and candidates for a particular precinct. Ballot styles vary based on which combination of contests and which party affiliation (in primary elections), that voters are eligible to participate in. Ballot style varies based on the contests voters are eligible to vote on and, during primary elections, their party affiliation. • Ballot Subset: Portion of a ballot that a particular Voter is eligible to vote on. • Ballot Tabulation: Process of totaling, or tallying votes. • Ballot Write-In Voting Position: For selected offices on the ballot, space is available for the voter to write-in the name of a candidate not listed on the ballot and mark its voting position. • Blank Ballot: A ballot on which there are no voting position marks that can be read by the voting system. • Candidate: A person who is seeking nomination or election to a specified office and who either has met the legal requirements to have his/her name printed on the ballot or is eligible to have his/her name written in on the ballot and counted as the voter's choice for the contest. • Canvass: Aggregating or confirming every valid ballot cast and counted, which includes absentee, early voting, Election Day, provisional, challenged, and uniformed and overseas citizen. 6/18/2024 12 Version: 5.19::4 Chapter 1 - Introduction • Central Count System: A voting system that tabulates ballots from multiple precincts at a central location. Voted ballots are placed into secure storage at the polling place. Stored ballots are transported or transmitted to a central counting place which produces the vote count report. • Central Counting Location: The place where the following operations occur: • Tabulate ballots or accumulate the results of previously tabulated ballots at one or more Central Counting Locations. • Merge the voting data produced by dissimilar voting systems. • Program or reprogram ballot-tabulating devices after Opening the Polls. • Certification Message: A message, followed by signature lines, which may be printed on reports attesting that the statistics and results are true to the best of the Precinct Board's/Central Count Operator's knowledge. • Contest: (1) A single decision or set of associated decisions being put before the voters (for example, the option of candidates to fill a particular public office or the approval or disapproval of a constitutional amendment). This term encompasses other terms such as “race,” “question,” and “issue” that are sometimes used to refer to specific kinds of contests; (2) A legal challenge of an election outcome. • Contest Headers: Space on the displayed ballot image where the contest name is shown. • CPU (Central Processing Unit): Commonly used abbreviation to describe the central processing unit of a computer or computer system as distinguished from other peripheral devices or components. • Demonstration Ballot: A ballot used for demonstration purposes, which displays a mock election. Such ballots may be used and re-used for demonstrations from election to election. • Diagnostic Messages: Appropriate message printed by the election log, under certain conditions, which indicates a problem or condition, as well as the recovery procedure. Such messages are tracking points in the audit trail. • Election: A formal process of selecting a person for public office or of accepting or rejecting a political proposition by voting. • Election Cycle:Represents all activity required to conduct an election. Comprised of the following electionphases: • Pre-election: Includes all preparation activities occurring before opening the polls. • Election: Includes all activities occurring during the election, including opening the polls or vote centers, conducting the election, and closing the polls or vote centers. • Post-Election: Includes all activities occurring after closing the polls. 6/18/2024 13 Version: 5.19::4 Chapter 1 - Introduction • Election Database: Database created for each election that defines the appropriate election parameters, attributes and other election-specific information. • Election: The phase of the election, which allows for official ballots to be cast, during the official election. Includes all activities occurring during the following sub-phases: • Opening the polls or vote centers • Election • Closing the polls or vote centers • Election Definition Cycle: The step-by-step processes used to program ® and prepare an election using the Democracy Suite Election Management System's set of applications. • Election Definition Files: A term used to collectively describe both device configuration and voter information files, which are stored on ® Compact Flash cards within the ImageCast series of tabulators. • Election Event Designer (EED): The primary pre-voting end user application used to define, design, and program an election event. • Election Management System (EMS): A set of applications for all pre- voting and post-voting activities accomplished in the process of defining and managing an election. These applications include Election Event Designer, Results Tally & Reporting, Audio Studio, Election Data Translator, Results Transfer Manager, Adjudication, Application Server Manager and Data Center Manager. • Election Official (EO): Applies to the county clerk, the county registrar of voters, the city clerk, or any other person who has been properly and legally charged with the responsibility of conducting the election. They may deputize others to perform functions. • Election Programming: Process by which election officials or their designees use voting system software to logically define the ballot for a specific election. • Election Stage: Individual operational activity, which occurs within an election phase. Several election stages make up an election phase. Some election stages are required, others are optional. • 'Famous Names' Ballot: A mock election ballot with historic figures running for fictitious offices. This ballot is intended for both demonstrations, and Accuracy Tests. ® • ImageCast Adjudication: The application that is used to examine and adjudicate ballots scanned. 6/18/2024 14 Version: 5.19::4 Chapter 1 - Introduction ® • ImageCast Central (ICC): A central ballot scan tabulator coupled with a ballot processing application, which is primarily used to process absentee ballots. ® • ImageCast Evolution (ICE): A precinct voter-fed paper ballot tabulator with an integrated inkjet ballot marking device and touchscreen. ® • ImageCast Precinct 2 (ICP2): A precinct voter-fed paper ballot tabulator with a touchscreen. ® • ImageCast X (ICX): A precinct ballot marking device. • iButton Security Key: A computer chip enclosed in a 16mm-thick stainless steel capsule, used as an administrative security key for accessing ® secured menus within the Democracy Suite set of products and applications. • Initialization: Process of returning a computer to its original state when the program was first to run, by returning all counters to zero or their starting values. • Logic and Accuracy Test (LAT): Tests which must be run before processing official ballots for an election. The logic test group of ballots has predetermined totals for all contests on the ballot. • Machine Behavior Settings (MBS): The settings that hold configuration parameters as defined by EMS applications and passed onto the ICE, ICC and ICP2. These settings define and determine the behavior of the ICE, ICC and ICP2 during an election. • Maintenance Diagnostics: Series of software and hardware tests and system utilities that allow for troubleshooting and setting system parameters. • Network: An interconnected system of transmission lines that allows the following to communicate with each other: • Computers • Terminals • Peripheral Devices • Similar types of equipment • Network Attached Storage (NAS): A server-side repository used for storing files and data related to the election cycle. • Non-Partisan Offices: Elected offices for which candidates run without political party affiliation. • Official Canvass: Consists of the post-election processing of all valid Vote- By-Mail (VBM), write-in, and provisional ballots, an audit of the counting process, and reporting of final results to the secretary of state (SOS). 6/18/2024 15 Version: 5.19::4 Chapter 1 - Introduction • Official Election: Election sub-phase, when voters cast official ballots for their candidate choices. • Open Primary: Primary election in which any voters can participate, regardless of their political affiliation. Some states require voters to publicly declare their choice of party ballot at the polling place, after which the poll worker provides or activates the appropriate ballot. Other states allow the voters to make their choice of party ballot within the privacy of the voting booth. • Opening the Polls: Election day sub-phase, which allows for opening the polls, for the official election sub- phase. • Overvote: When the number of selections made by a voter in a contest is more than the maximum number allowed. • Overvoted Ballot: A ballot where the voter has voted for more than the allotted number of candidates for one or more offices being contested. • Paddles: Hand or foot-operated switches attached to the ATI. Paddles are used to navigate and make selections to the ballot during an accessible voting session. • Partisan Offices: An elected office for which candidates run as representatives of a political party. • Post-Election: Election phase, which includes all activities occurring after closing the polls. • Post-Election LAT (Logic and Accuracy Tests): Optional post-election function, which includes post-election logic and accuracy tests, for ballot verification and public oversight of ballot integrity. • Pre-Election: An election phase, which includes all activities occurring before opening the polls. • Pre-Election LAT (Logic and Accuracy Tests): Pre-Election function, which includes mandatory logic and accuracy tests, which are performed during pre-election, for electronic verification and public oversight of ballot integrity. • Precinct Count System: A voting system that tabulates ballots at the polling place. These systems typically tabulate ballots as they are cast and print the results after the closing of the polls. With an Optical Scan System, after ballots are marked either by hand or with a ballot marking device, they are tabulated when a ballot is placed into the scanner. These systems provide electronic storage of the vote count and results are later uploaded to a central election management system. • Printer (thermal): System component that is used to produce reports of the vote tally. 6/18/2024 16 Version: 5.19::4 Chapter 1 - Introduction • Protective Counter: A function of the ballot tabulator, which includes a counter that records the number of all of the ballots tabulated since the device was built. • Provisional Ballot: A ballot cast by a voter who was not on the list of eligible voters, whose information was incomplete or not accurate, or who had already received a ballot in the mail and was allowed to vote. Fail-safe ballots are usually kept separate from the other ballots until an election official can determine if the voter is eligible to vote. These ballots are sometimes called fail-safe ballots. • Provisional Voting: The act of casting a ballot by a voter who was not on the list of eligible voters, whose information was incomplete or not accurate, or who had already received a ballot in the mail and was allowed to vote. Provisional ballots are usually kept separate from the other ballots until an election official can determine if the voter is eligible to vote. These ballots are sometimes called fail-safe votes. • Public Counter: Counter in a voting system that counts all the ballots cast in a single election or election test in a manner that is visible to the user and/ or public. • Recall Voting: Process that allows voters to remove elected representatives from office prior to the expiration of their terms of office. • Results Tally & Reporting (RTR): The primary post-voting user application that integrates election results acquisition, validation, tabulation, reporting, and publishing capabilities. • Rotation: Process of varying the order of the candidate names within a given contest. This practice varies by state. • Secrecy Sleeve: An envelope or folder of such design and dimensions used to hide the voted ballot to ensure voter's privacy. • Semi-official Canvass: The process of collecting processing, and tabulating ballots on election night. This may include reporting results to the Secretary of State. The semi-official canvass may include some or all of the absentee vote totals. The semi-official canvass is contrasted with the official canvass which begins no later than the first Thursday following the election and, for statewide elections, must result in final certification 28 days following the election. • Sip & Puff: A pneumatic breath-operated switch attached to the ATI and used to navigate, and make selections on a ballot during an accessible voting session. • Split Precinct: A precinct that contains an election district subdivision, e.g., parts of the precinct are in different political jurisdiction such as a water district or school board district, requiring an additional ballot configuration. 6/18/2024 17 Version: 5.19::4 Chapter 1 - Introduction • Spoiled Ballot: A ballot which has been mistakenly marked or altered by a voter. A spoiled ballot is not cast, and the voter may request a new ballot to mark correctly. • System Proofing: Procedure which verifies that all materials, files, and programs for an election are correctly prepared. This proofing is normally done in approximately two (2) weeks, during the period consisting of 40 days to approximately 14 days prior to election day. Logic and accuracy tests are included in system proofing. • Test Deck: A pre-marked stack of ballots which will generate a predictable pattern of results, when scanned into a tabulator programmed for that election project. This deck would be used for accuracy testing. • Undervote: Occurs when the number of choices selected by a voter in a contest is less than the maximum number allowed for that contest or when no selection is made for a single choice contest. • Undervoted Ballot: A ballot where the voter has voted for less than the total number of election contests listed on the ballot, or less than the number of positions to be filled for a single office. ® • Virtual Outstack: A function within the ImageCast Central application where ballots containing voter exceptions (e.g. misread, an overvote, undervote, blank, ambiguously marked ballots) will halt the scanning process and notify the operator which ballot in the batch contains the voter exception. • Vote By Mail Ballots: See absentee ballots. • Vote For: To cast a ballot in favor of a political candidate or proposition. • Voted Ballot: Ballot that contains all of a voter's selections and has been cast. • Voter Information Files (VIFs): Election information including, but not limited to, ballot layouts, contests, and candidate names, that are stored on the CompactFlash cards within the tabulator. • Write-In: A vote for a candidate that was not listed on the ballot. In some jurisdictions, voters may do this by filling in a write-in space provided on a paper ballot, or they may use a keypad, touch screen, or other electronic means to enter the name on an electronic voting device. • Write-In Ballot: A ballot where a vote has been cast in a race for a candidate whose name does not appear on the ballot. • Write-In Candidate: Optional candidate type used to provide a means for the voter to write the name of a candidate whose name does not appear on the ballot. 6/18/2024 18 Version: 5.19::4 Chapter 1 - Introduction 1.4 Use Procedure Summary In the period prior to the election, it is necessary to perform several levels of tests, each having a different role in the period leading to the election. This includes: 1. Acceptance Testing: This is a test executed upon receiving the hardware equipment in order to verify that the equipment is in good working order. 2. System Readiness Testing Procedures: This test is run after installing ® and configuring the whole Democracy Suite system. The goal is to verify that products are configured to run as an integrated system. The test consists of pre-voting, voting and post-voting phases. 3. Logic and Accuracy Test: This test is a rehearsal run prior to an election to confirm everything runs and operates as intended, including the very election project that is programmed for that specific election. Therefore, this test is run with actual election files that are going to be used during the election. If successful, the results are backed up and archived, and then that same system, equipment and files are used in an actual election (including CF Cards, applicable Smart Cards, iButtons, ballots etc.). In this test, every tabulator defined in the election project must be tested. In addition to the tests listed above, this document describes the election day ® (period) use procedures for running an actual election on the Democracy Suite platform. These steps are similar to the logic and accuracy test procedure, with differences in equipment preparation and handling, and backup/restore tasks. The procedure related to the election period assume that the logic and accuracy test was completed and starts from the chapter Post-L&A Preparation for Election Day. All tests mentioned above are described in detail in the following chapters. Prior to executing the logic and accuracy test, ensure that the system is configured as specified in chapter 3“System Installation and Configuration”. The procedure suggested in this document is based on the following set of assumptions: 6/18/2024 19 Version: 5.19::4 Chapter 1 - Introduction NOTE: The procedure suggested in this document is based on the following set of assumptions: ® • The Adjudication application is a part of the Democracy Suite configuration. • Automated loading of results is enabled in the RTR application. ® • ImageCast Voter Activation (ICVA) station may be a part of the Democracy ® Suite configuration. For any case for which the above assumptions are not true, Dominion Voting Systems will provide a modified procedure to suit the specific scenario, if required. The following is a condensed list of recommended use procedure steps: 1. Restore the election project and import the encryption certificate (refer to 12.2.2"Restoring an Election Project”) database received from the Dominion Voting as well as all other artifacts required for the election’s successful execution. Alternatively, the jurisdiction might build the projects and related artifacts themselves. 2. Get election data media and other artifacts ready: a. Program the iButton security keys (refer to D.2.7.2"Programming of iButton Security Key”) in EED. b. Program the CF and SD cards (refer to D.2.7.1 "Programming of CF/SD Cards”) in EED. c. Program the poll worker Smart Cards (refer to D.2.8"Programming of poll worker Smart Card”) in EED. d. Program the USB media (refer to D.2.7.4"Program USB flash drive for ImageCast X Devices”) in EED. e. Export activation codes (refer to D.3"Exporting of Voter Activation Codes from EED”), save the file on the removable media and transfer it to the ICVA station to configure the ICVA application. f. Prepare the test decks (refer to 4.2.2"Performing the Voting Phase Readiness Test”) with known results. 3. Load results per the jurisdiction’s procedures. 4. After polls have closed, load results from the CF and SD cards (refer to 8.2.1 "Loading Results from Removable Media Management”) that had been installed in election day ICE and ICP2 tabulators, with the option to adjudicate or skip adjudication before importing the results. 6/18/2024 20 Version: 5.19::4 Chapter 1 - Introduction 5. Load results from the CF/SD cards (refer to 8.2.1"Loading Results from Removable Media Management”) that had been installed in early vote ICE ® and ICP2 tabulators - (refer to 8.2.6.1"Early Vote ImageCast Evolution and ImageCast® Precinct 2”), with the option to skip adjudication or to adjudicate. 6. Validate and publish all results (refer to 8.2.4"Validate and Publish Results”). 7. Run the summary report (refer to 8.2.5 "Election Night Summary Report - Election Day Report”). This report is run on election night and contains a mix of adjudicated and un-adjudicated result files. 8. In the period beginning the day after the election: a. Select all result files in “Skipped Adjudication” status and click Reject. This will change the status from “Published” to “Rejected”. b. Then, select those same result files and click Reset - this action will change the state of those result files from "Rejected" to "Initial". c. Finally, click Allow Adjudication for all those result files that will result in their adjudication state being transformed from “Skipped” to “Pending Adjudication”. 9. Adjudicate remaining result files, resolving write-ins in the process (see Sections 9.1 “Adjudication Overview” and 9.8“Adjudicating Ballots”). 10. Handle any provisional ballots and any ballots that need to be remade. 11. Once completed, validate and publish all result files and run Statement of Votes Cast and/or Canvass reports. 12. If the procedure is done during the L&A testing, then: a. Back up all results (see 12.2.1“Backing Up an Election Project”), backup ® ImageCast Central Tabulator Folders and back up of the adjudication ® databases (refer to 7.3"Backing Up ImageCast Central Files From Prior Elections”). b. Purge results (refer to 12.4"Purging Election Results”) from the system. c. Prepare equipment for the election (refer to 3.2"Hardware and Network Set-up and Configuration”). 13. All results should be backed up as per jurisdictional procedures and as described in chapter 10.9“Backup and Retention of Election Material”. 6/18/2024 21 Version: 5.19::4 Chapter 2 - Ballot Definition CHAPTER 2: BALLOT DEFINITION 2.1 Overview ® Ballot layout for all Democracy Suite products is accomplished in the Election Management System Election Event Designer application during the election definition process. Ballots are generated as tabulator-ready PDF ballot artwork files. 2.2 Ballot Artwork Source Files ® Dominion’s Democracy Suite Election Management System (EMS) creates tabulator-ready PDF ballot artwork files. Ballot artwork files are created as complete ballot images, which can be created with or without trim lines or crop marks, and are designed to directly print on digital 4-color sheet-fed xerographic or other electrophotographic printers (most B-sized laser printers). Ballot artwork is generated in industry-standard PDF Version 1.3 and CMYK color space. Ballot artwork files are full-sized press-ready ballots containing all required ballot elements and the unique ballot ID barcode that distinguishes each ballot style. Each file contains one or two ballot images: a front image (if the ballot is single- sided) or paired front and back ballot images. All fonts used in the ballot artwork are embedded in the PDF file. Ballot artwork files are digitally-signed (X.509) and ® tied to the election project files produced by Democracy Suite EMS to allow for authentication and revision control. The file naming scheme used for the ballot ® artwork files is set in Democracy Suite EMS and is controlled by the election administrator. Typical file names might be as simple as “1.pdf ” or can be as descriptive as “ballot 4324 A01 B EP 20100912 0.pdf ”. An election administrator will provide a list of the ballot artwork file names and usage. ® Pre-press imposition of ImageCast ballot artwork to add crop or alignment marks, jurisdiction-mandated background screens, stub artwork, or other printing, may be required. No modifications, post-processing, or image conversion of the original ballot artwork files is allowed. 2.3 Paper and Printing Specifications ® ImageCast ballots can be easily printed by a range of modern printing technologies. 6/18/2024 22 Version: 5.19::4 Chapter 2 - Ballot Definition • Small quantities of tabulator-ready ballots can be printed with a conventional B-size laser printer (600 dpi min., pre-calibrated), directly ® onto pre-cut blank ballot stock. ImageCast ballot artwork files are pre- ® configured for this use. In-house laser printing of ImageCast proofing and test ballots allows a jurisdiction to quickly and easily test the Democracy ® Suite EMS election project setup and tabulation options. • Most jurisdictions choose a Dominion-certified print vendor to produce the ® ballots that will be used for their election. ImageCast ballots are often produced by conventional web or sheet-fed offset lithographic presses. • High-speed digital xerographic or other electrophotographic presses (both ® web and sheet-fed) have also been used to produce ImageCast ballots. • Inkjet printers, from small desktop units to high-speed web print engines, ® have produced millions of ImageCast ballots. 2.4 ImageCast®Ballot Stock Selection ® ImageCast ballots are printed on high-quality, dimensionally stable, opaque text and cover paper from selected manufacturers. As a result of the high precision required in ballot scanning and vote tabulation, Dominion only recommends ballot stock that has been tested to have a low dirt content and low numbers of ® imageable defects for ImageCast ballot production. Approved paper stocks are still subject to additional inspection on a lot-by-lot basis for dirt and other defects in the paper that may be imaged by our tabulators. A range of paper weights (basis weight or grammage) can be used, depending upon the type of ballot being ® printed and the ImageCast tabulator used. Ballots marked by voters at the polls and hand-fed into tabulators are usually printed on heavier weight cover or text stocks. Ballots designed for mail distribution are often printed on lighter weight stocks. The election administrator may indicate a preference for varying the weight of the stock for the different types of ballots, or the entire election may be printed on a single weight of paper. Multiple paper weights do not pose problems ® for the tabulator so long as the weight is an approved ImageCast commercial ballot paper. Ballot stock is available in both rolls and sheets, and comes in a variety of sizes to accommodate the different ballot printing technologies and presses. If the selected presses or finishing equipment are limited to certain paper stocks, please ® inform the election administrator before bidding. Most ImageCast ballots are printed on approved #100 opaque text or #80 opaque cover stocks. This yields a dimensionally-stable ballot card that is durable, easy to print, and widely accepted by voters. 6/18/2024 23 Version: 5.19::4 Chapter 2 - Ballot Definition 2.5 Approved Ballot Paper Stocks The text and cover paper stocks that have been tested and approved for ® manufacturing ImageCast ballots are listed in the table below. All approved ballot stock is white, bright white, or natural colored paper and has a smooth finish. Color-coding ballots is normally achieved in the ballot artwork by printing screened area(s) of color as a background as required by California Elections Code section 13002 – not by ordering colored ballot stock. Manufacturer Ballot Weight Color / Finish Recommende Production d Paper Print Method Rolland Toner Based 100# Text Bright White, VoteSecur SL Enterprises Inc Smooth Finish Rolland Inkjet 100# Text Bright White, VoteSecur IJ Enterprises Inc Smooth Finish Rolland Offset 100# Text Bright White, VoteSecur Enterprises Inc Smooth Finish Table 2-1: Paper Stock Approved for ImageCast Ballots 6/18/2024 24 Version: 5.19::4 Chapter 3 - System Installation and Configuration CHAPTER 3: SYSTEM INSTALLATION AND CONFIGURATION 3.1 Hardware Requirements and Specifications This section includes information about the hardware components required for your election. The following sections list the components at a high-level only. For detailed information regarding the hardware components and configuration, ® please see the 3.11 Democracy Suite Configuration Management Plan document. 3.1.1 Election Management System Hardware Requirements • Server - Dell PowerEdge R660 • Workstation - Dell Precision 3460 XE • Laptop - Dell Latitude 3340 • Laptop - Dell Latitude 3420 • Laptop - Dell Latitude 3410 • Laptop - Dell Latitude 3400 • Laptop - Dell Latitude 3490 • Laptop - Dell Latitude e3480 • Monitor (2) - 24" • Compact Flash memory card, 4 GB • Compact Flash memory card, 8 GB • Compact Flash memory card, 16 GB • Compact Flash memory card, 32 GB • Smart card • Ethernet Switch • UPS • Mini Server Rack • Single iButton programmer with USB adapter 3.1.2 ImageCast® Central Hardware Requirements • ICC Scanner: Canon DR-G2140 • ICC Scanner: InoTec HiPro 821 with integrated imprinter • Single iButton programmer with USB adapter 6/18/2024 25 Version: 5.19::4 Chapter 3 - System Installation and Configuration • Monitor, 24" • Touchscreen monitor, 24" • Canon Scanner Client Workstation Configuration: • Dell Precision 3460 XE • Dell Precision 3440 XE • Dell OptiPlex 5270 • Dell OptiPlex 3050 • InoTec HiPro Scanner Client Workstation Configuration: • Dell Optiplex XE4 • Dell Optiplex 7070 • Dell Optiplex 7060 • Dell Optiplex 7050 • USB 3.0 flash drive, 8 GB • Single iButton touch and hold reader / programmer • UPS 3.1.3 ImageCast® Evolution Hardware Requirements • ImageCast Evolution tabulator (PCOS-410A) • Compact Flash memory card, 4 GB • Compact Flash memory card, 8 GB • Compact Flash memory card, 16 GB • Compact Flash memory card, 32 GB • Battery, PCOS-410A, lithium ion, 14.8v, 8.8ah with LED display and plastic case • Audio tactile interface unit (ATI) • Headphones, stereo soft foam ear pad with adjustable plastic headband • Tube style sip and puff device • DS1963 iButton 4kbit read/write data carrier 3.1.4 ImageCast® Precinct 2 Hardware Requirements • ImageCast Precinct 2 tabulator (PCOS-330A) • SDHCmemory card,8GB 6/18/2024 26 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.1.5 ImageCast® X Hardware Requirements • Touchscreen tablet, 21" • Printer - HP M402dn • Printer - HP M402dne • HP M404dn • HP 4001dn • Centon USB • Smart Card 3.2 Hardware and Network Set-up and Configuration ® Democracy Suite system installation and configuration procedures are described ® in Democracy Suite EMS Standard System Installation and Configuration Procedure. The Democracy Suite® EMS platform consists of multiple components, including ® Election Management System and ImageCast Central workstations. They are configured in a EMS Standard Hardware Configuration. In-person voting components may consist of ImageCast Evolution, ImageCast Precinct 2 and ImageCast X Ballot Marking Devices. The EMS Standard hardware configuration provides a client-server local LAN deployment environment. This hardware configuration separates client and server system components by utilizing a single physical server device to run all EMS server components. Client PC computers running EMS client applications are interconnected with the back-end server component through the gigabyte LAN network which utilizes the smart network switch. The clients include adjudication workstations, EMS workstations and ICC workstations as shown in Figure3-1 and Figure3-2. ® The Democracy Suite system is capable of being deployed in a segregated dual- installation architecture to protect against propagation of viruses. The architecture allows elections officials to use one or more permanent server(s) to: 1) program the elections and create memory cards prior to the election; and 2) to use another, physically separate, “sacrificial” server and set of voting devices after the election to tabulate results and generate reports. This segregated dual-installation architecture is achieved by installing and configuring the Election Management System onto the two physically separate ® machines, a procedure outlined in the Democracy Suite EMS Standard System Installation and Configuration Procedure document. One installation is then to be used as a primary/permanent server for creating the election project, ballot 6/18/2024 27 Version: 5.19::4 Chapter 3 - System Installation and Configuration artwork, and producing the election files for programming the central and precinct voting machines/devices to be used in the election. Then, after the election project is complete (i.e., in "Ready for Election" status), the project is backed-up and transferred to the sacrificial server using a USB removable medium. Once the project is restored on the sacrificial server, it is used for tabulating results as well as generating election and audit reports. The two systems exist on their own isolated networks, thereby preserving their physical separation and ensuring that data cannot flow between installations/networks. Prior to attempting to execute the use procedure as defined in this document, the system must be configured as defined in this chapter. The configuration of each of the system components is related to specific functionality which needs to be executed, enabled, configured and/or set in a particular manner that enables the use procedure workflow outlined in this document to be executed on the ® Democracy Suite system. Figure 3-1: EMS/RTR Air-gap Network Configuration 6/18/2024 28 Version: 5.19::4 Chapter 3 - System Installation and Configuration Figure 3-2: EMS/EED Air-gap Network Configuration 3.2.1 Air-gap Configuration When setting up an air-gap configuration, the following isolation method is used (see Figure3-3 for reference). Figure 3-3: Air-gap Isolation 6/18/2024 29 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.2.1.1 Air-gap Configuration Details The diagram below details the following air-gap configuration: 1. EED Server used for the following: • Election definition • Machine programming (Creation of memory cards and devices) 2. RTR Server (reformatted after each election) used for the following: • Reading and tallying results • Reporting, tallying and adjudication 3. Reformatting workstation used for the following: • Reformatting CF and SD cards and memory devices before introduction to the permanent system 3.2.1.2 Performing Cryptographic Erase on Standard Server This task consists of the following procedures, each of which is elaborated step- by-step below: • First, any existing RAID disks must be removed. • Then, the disks will be erased using cryptographic erase. • Then, you need to create new RAID disks. If RAID disks have never been created on this system you may skip the first procedure, and proceed to the second procedure. (1) To Delete Preexisting RAID Disks: 1. Turn on the EMS Standard Server. 2. During the boot sequence, press F2 to open the System Setup Main Menu. 3. Click Device Settings. The Device Settings page displays. 4. Select Integrated RAID Controller 1. The Integrated RAID Controller 1 Main Menu displays. 5. Click Configuration Management. 6. Click Clear Configuration. The Warning page is displayed. 7. Select Confirm and then click Yes. The Success page displays. 8. Click OK. The Configuration Management page is displayed. 6/18/2024 30 Version: 5.19::4 Chapter 3 - System Installation and Configuration 9. Click View Disk Group Properties. The View Disk Group Properties page displays. 10. Confirm that “No Virtual Disks found in the system” is displayed. 11. Click Back until you return to the Integrated RAID Controller 1 Main Menu. (2) To Perform Cryptographic Erase: 1. Turn on the EMS Standard Server. 2. During the boot sequence, press F2 to open the System Setup Main Menu. 3. Click Device Settings. The Device Settings page displays. 4. Click RAID Controller. The Dashboard View page displays. 5. Click Main Menu. The Main Menu page displays. 6. Click Controller Management. The Controller Management page displays. 7. Click Advanced Controller Management. The Advanced Controller Management page is displayed. 8. Click Perform Cryptographic Erase on Disks. The Perform Cryptographic Erase on Disks page displays. 9. Click Check All. 10. Click Go. A Warning page displays. 11. Click Yes. A Warning page displays. 12. Click OK. The Advanced Controller Management page displays. (3) To Create a RAID1 Virtual Disk: 1. Turn on the EMS Standard Server. 2. During the boot sequence, press F2 to open the System Setup Main Menu. 3. Click Device Settings. The Device Settings page displays. 4. Click RAID Controller. The Dashboard View page displays. 5. Click Configuration Management. 6/18/2024 31 Version: 5.19::4 Chapter 3 - System Installation and Configuration 6. Click Create Virtual Disk. The Create Virtual Disk page displays. 7. From the Select RAID Level drop-down, select RAID1. 8. Click Select Physical Disks. 9. In the CHOOSE RAID CAPABLE DISKS section, select the first two disk drives and then click OK. A message displays: “The operation has been performed successfully.” 10. Click OK. The Create Virtual Disk page displays. 11. Select Secure Physical Disks. 12. In the Virtual Disk Name field, enter OS. 13. Set Initialization to Fast. 14. Click Create Virtual Disk. The Warning page displays. 15. Click Confirm and then click Yes. A message displays: “The operation has been performed successfully.” 16. Click OK. The Create Virtual Disk page displays. (3) To Create a RAID10 Virtual Disk: 1. On the Create Virtual Disk page, from the Select RAID Level drop-down, select RAID10. 2. Click Select Physical Disks. The Select Physical Disks page displays. 3. In the CHOOSE RAID CAPABLE DISKS section, click Select All and then click OK. A message displays: “The operation has been performed successfully.” 4. Click OK. The Create Virtual Disk page displays. 5. Select Secure Virtual Disk. 6. In the Virtual Disk Name field, enter DATA. 7. Set Initialization to Fast. 8. Click Create Virtual Disk. The Warning page displays. 9. Click Confirm and then click Yes. A message displays: “The operation has been performed successfully.” 10. Click OK. 6/18/2024 32 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.2.1.3 Dell Data Wipe (Dell 3400 Computers) The following procedure should only perform the following procedure on computers with a solid-state drive (SSD). 1. Power on computer. 2. When the Dell logo appears, press F2 to enter the BIOS setup menu. 3. Select the Maintenance menu. 4. Set Start Data Wipe: ON (enabled). 5. Click OK to confirm. 6. Click No. 7. Click Apply Changes. 8. Click OK. 9. Click Exit. 10. On boot, select Continue and then press Enter. 11. Select ERASE and then press Enter. 3.2.1.4 Dell Data Wipe (Dell 7050/7060 Computers with Solid State Drive SSD) The following procedure should only perform the following procedure on computers with a solid-state drive (SSD). 1. Power on computer. 2. When the Dell logo appears, press F2 to enter BIOS setup menu. 3. Scroll or move mouse cursor to Maintenance and select Data Wipe. 4. Inside the Data Wipe menu, select the Wipe On Next Boot checkbox. 5. Click OK to confirm. 6. When the warning message appears, click Yes. 7. Click Exit. 3.2.1.5 Dell Data Wipe Instructions (Dell Precision 3460 XE) The following procedure should only perform the following procedure on computers with a solid-state drive (SSD). 1. Power on Computer. 2. When the Dell logo appears, press F2 to enter the BIOS setup menu. 3. Select the security menu. 4. Turn on start data wipe. 6/18/2024 33 Version: 5.19::4 Chapter 3 - System Installation and Configuration 5. Click OK to continue the operation. 6. A warning message appears. Click No. 7. Click Apply Changes. 8. Click Exit. 9. Restart the workstation. 10. On reboot click Continue to perform the data wipe operation. 3.2.1.6 Dell Data Wipe Instructions (Dell Optiplex XE4) The following procedure should only perform the following procedure on computers with a solid-state drive (SSD). 1. Power on Computer. 2. When the Dell logo appears, press F2 to enter the BIOS setup menu. 3. Select the security menu. 4. Turn on start data wipe. 5. Click OK to continue the operation. 6. A warning message appears. Click No. 7. Click Apply Changes. 8. Click Exit. 9. Restart the workstation. 10. On reboot click Continue to perform the data wipe operation. 3.2.1.7 Connect Equipment • Connect all computers, printers, scanners and network switch to power sources. • Connect all keyboards, mice and iButton readers, and scanners to rear USB ports. Leave the front/side ports clear for thumb drives, etc. • Connect the monitor to the server using the VGA cable. • Connect the monitor to EMS client and ADJ clients using the DisplayPort cable. 3.2.1.8 Record Service Tags Record the service tags for the Dell equipment (server(s), computers, switch(es) ® and monitors) and serial numbers of the ImageCast Central scanners in the county installation worksheet. Email the serial numbers to the customer relations manager. 6/18/2024 34 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.3 Upgrade EMS and Tabulators This section describes how to upgrade the Democracy Suite EMS infrastructure and tabulators. The complete upgrade process involves the following phases: 1. Software upgrade of EMS servers, EMS clients, Adjudication clients, ICC clients and ICVA laptops. The upgrade is performed by deploying preconfigured images and performing post-imaging procedures, detailed in this document. 2. Software installation of the ICX voting terminals. Full upgrade instructions and additional information are provided in the ICX installation document, ® included with the Democracy Suite 5.19 TDP. 3. Firmware upgrade of the ICP 2 voting terminals. Step-by-step instructions are provided in the ICP 2 installation document, included with the ® Democracy Suite 5.19 TDP. 4. Firmware upgrade of the ICE voting terminals. Step-by-step instructions are provided in the ICE installation document, included with the Democracy ® Suite 5.19 TDP. This chapter covers the imaging and configuration steps for the following systems: • EMS Standard Server • EMS Client Workstation • ADJ Client Workstation • ICC Workstation • ICVA laptop Tabulator hardware and software upgrade steps are covered in separate documents. 3.3.1 Before Beginning the Upgrade Before beginning the upgrade process the following steps must be completed: 1. All Election Databases should be backed up and transferred to an external media for migration to the upgraded system. 2. Any reports or files that need archived should be moved to an external media to be migrated to the upgraded system. 3. If a Cepstral License file has not been provided, the licensing should be copied and moved to the external media to be applied after upgrading. 6/18/2024 35 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.3.2 Upgrading the EMS Standard Server This section describes how to upgrade the EMS Standard Server from version 5.10-A to version 5.19. 3.3.2.1 Standard Server Checklist The following checklist provides a quick reference for the steps that you must perform when upgrading the county’s computer or server systems. No. Item Complete 1. Connect to Trusted EMS Switch 2. Update BIOS/Firmware 3. Configure BIOS/iDRAC Settings Configure RAID with self-encrypting drives / Pre-deploy- 4. ment BIOS configuration 5. Deploy Golden Image 6. Apply Windows Activation Key and Activate Windows 7. Enabling Client Accounts/Adding Users 8. Apply county specific credentials to all users 9. Apply Cepstral Voice Licenses 10. Verify Time Zone, Date, and Time 11. Re-run the Data Center Manager 12. Configure Report Printer Download and Apply the Latest Windows Defender 13. updates 14. Apply Hardening 15. Apply Post Hardening BIOS Settings 16. Acceptance Test Table 3-1: EMS Standard Server 3.3.2.2 Installing Lifecycle Controller, BIOS Updates, and Drivers To install the Lifecycle Controller, BIOS updates, and drivers: 1. Ensure the EMS Standard Server is turned off. 6/18/2024 36 Version: 5.19::4 Chapter 3 - System Installation and Configuration 2. Connect the USB media containing the update files to the EMS Standard Server. 3. Turn on the EMS Standard Server and press F10 to go to Life Cycle Controller. 4. At the Home screen click Get the latest firmware. 5. At the Select Update Repository screen click Local Drive, then click Next. 6. At the Enter Access Details screen, click Browse. 7. Select the Local Drive field and select the USB media. 8. Select the File Path or Update Package Path and select the iDRAC with Lifecycle Controller update file. 9. After selecting the file, click OK. The Enter Access Details screen displays. 10. Click Next. 11. At the Select Updates screen, under Component select the component's update check-box and then click Apply. 12. To verify the update, at the Home screen click Firmware Update > View Current Versions. 13. Verify the updated versions. 14. Return to step 4 and repeat the procedure for each of the remaining update files provided on the installation media. 15. After you have installed all the updates, click Exit. The Warning dialog displays. 16. Click Yes. The EMS Standard Server restarts. 3.3.2.3 Configuring BIOS, iDRAC and Verifying RAID Configuration/ Enabling Self-Encrypting Drives (EMS Standard Server) BIOS settings may already be set, but they should be reset to default and reconfigured to ensure they are correct and consistent. EMS Standard Servers should be configured with two virtual discs in the RAID controller. A Raid 1 (Used for OS) and a RAID 10 (Used for the Data), both disks should be configured with self-encrypted drives. Each system will likely have a previously set BIOS password (Setup password). This password will need to be entered when attempting to change BIOS settings and when booting from the Acronis media. To configure BIOS and iDRAC, follow these steps: 6/18/2024 37 Version: 5.19::4 Chapter 3 - System Installation and Configuration 1. During boot, press F2 when the prompts appear at the top of the screen. The “Entering-System Setup” option appears highlighted in blue. The system will enter the System Setup menu after the devices have been initialized. 2. Enter the BIOS Set-up password when prompted. 3. In the System Setup main menu, click System BIOS. 4. In the BIOS Settings menu, click Default, select Yes to confirm, and then click OK to finish. 5. Click SATA Settings, select the AHCI option, and then click Back. 6. Click Integrated Devices, set iDRAC Direct USB Port to OFF, and then click the Back button. 7. Click Serial Communication, select Off from the Serial Communication drop-down menu, and then click Back. 8. Click Finish. Confirm that the settings have changed by clicking Yes, and then click OK. 9. Click Finish to exit back to the System Setup main screen. 10. Click Finish, and then click Yes to confirm. 3.3.2.4 Creating a Security Key To create a Security key, follow these steps: 1. Turn on the EMS Standard Server. 2. During the boot sequence, press F2 to open the System Setup Main Menu. 3. Click Device Settings. The Device Settings page displays. 4. Click RAID Controller. The Dashboard View page displays. 5. Click Main Menu. The Main Menu page displays. 6. Click Controller Management. The Controller Management page displays. 7. Click Advanced Controller Management. The Advanced Controller Management page displays. 8. Click Disable Security. A Warning page displays. 9. Select Confirm and then click Yes. A Success page displays. 6/18/2024 38 Version: 5.19::4 Chapter 3 - System Installation and Configuration 10. Click OK. The Advanced Controller Management page displays. 11. Click Enable Security. The Enable Security (Choose Security Mode) page displays. 12. Click OK. 13. In the Security Key Identifier field, enter an identifier for the security key. 14. In the Security Key and Confirm fields, enter a security key. 15. Take note of the security key that you entered and save it in a secure location for future reference. 16. Select I Recorded the Security Settings for Future Reference. 17. Click Enable Security. A Warning page is displayed. 18. Click Confirm and then click Yes. A message displays: “The operation has been performed successfully.” 19. Click OK. 3.3.2.5 Enabling Secure Boot To enable secure boot: 1. Press F2 during the boot sequence. 2. Go to System BIOS. 3. Select System Security. 4. Set Secure Boot to Enabled. 5. Select OK. 6. Select Back and then press Finish. 3.3.2.6 Configuring the Thermal Settings You need to configure the thermal settings to ensure optimal performance. To configure the thermal settings, follow these steps: 1. Turn on the EMS Standard Server. 2. During the boot sequence, press F2 to open System Setup. 3. On the System Setup Main Menu page, click iDRAC Settings. The iDRAC Settings page displays. 4. Click Thermal. The Thermal page displays. 5. Set the following values: 6/18/2024 39 Version: 5.19::4 Chapter 3 - System Installation and Configuration • Thermal Profile: Maximum Performance (Performance Optimized) • Fan Speed Offset: Off • Minimum Fan Speed: Custom • PWM (% of Max range 14 - 100 percent): 25 6. Click Back. 7. Click Finish. 8. Click Yes. The thermal settings are configured. 3.3.2.7 Pre-Image Deployment BIOS Configuration To configure BIOS for pre-image deployment: 1. Select System BIOS from the System Setup menu. 2. Enter the System Setup password when prompted. 3. Click Boot Settings, set the Boot mode to UEFI, and then click the Back button. 4. If prompted by any informational messages, click OK. 5. Click Finish. 6. Click Finish to exit System Setup, and when prompted, click Yes to confirm the action. 3.3.2.8 Deploying the Image on the EMS Standard Server This subsection describes the image deployment procedure for the EMS Standard Server. Required: Acronis 2023N bootable media, SSD with golden images Before deploying the image: • Verify that all BIOS and RAID configurations have been successfully completed. To restore the image on the EMS Standard Server, first ensure the server is powered off, and then follow these steps: 1. Copy the Acronis backup image to an external hard disk. 2. Insert the Acronis bootable removable media device and external hard disk into the machine to be restored. 3. Power on the server. 4. Press F11. 5. Select the Acronis bootable removable media device. 6/18/2024 40 Version: 5.19::4 Chapter 3 - System Installation and Configuration 6. In section Recovery, select Browse for Backup... 7. Browse to the local folder location of the external hard disk where the image was copied, and then click OK. 8. From the Archive Name section, select the appropriate file (e.g., ‘Backup #1’). 9. Right-click the selected backup file and click Recover. 10. Select Recover Whole disks and partitions from recovery methods. 11. Select the recovery point of the chosen image. 12. From the What to recover screen that displays, select Disks, and then select Disk 1 and Disk 2. 13. From the destination of selected disks (see Step 12), select the disks from where the backups need to be recovered. 14. Click Proceed. The image restoration process initiates. 15. Once the Acronis restore is complete, restart the workstation, and then safely eject the removable media device and external hard disk. NOTE: When the server is booted for the first time after restoring the image, it may take some time for Windows to initialize the devices. This is normal. Wait until the initialization process is complete. 3.3.2.9 Activating Windows on the EMS Standard Server Before you activate Windows on the EMS Standard Server, ensure you have the following prerequisites: • Smartphone • Activation link To activate Windows on the EMS Standard Server: 1. Click Start and type ‘CMD’. 2. Right-click CMD and then select Run As Administrator. 3. Type ‘SLUI 4’ and press Enter. 4. Select region: United States, and then click Next. You should see the installation ID you need to use for activation (the installation ID will be 9 sets of 7 digits). To activate Windows by phone: 1. Call the number from your phone (855-801-0109). 2. Use these responses to get to the phone activation system or follow the prompts: 6/18/2024 41 Version: 5.19::4 Chapter 3 - System Installation and Configuration a. Do you consent to this call being recorded? Press 2 (No) b. When prompted, repeat the security phrase. c. When prompted, say “Activate windows”. d. Are you at your computer with the window open? Say “Yes”. e. When asked if you would like a link sent to the Smartphone, say “Yes”. 3. Once you have the link, hang up. 4. Open the link and select Windows, then Windows 11. 5. Enter the code from the screen, and then click Submit. 6. Enter the response code from the link into the activation window on the computer. 7. Once complete, close all windows. 3.3.2.10 Enabling Client User Accounts on the EMS Standard Server The server image is created with preconfigured client accounts for Adj, EMS and ICC clients. Depending on the county infrastructure client accounts will need to be enabled or additional accounts created accordingly. To enable User Accounts: 1. Right-click on the Windows icon and select Computer Management. 2. Expand Local Users and Groups and click Users to see the list of user accounts. 3. To enable a preconfigured user account, open the user and uncheck Account is Disabled. 4. Click OK. 5. Repeat these steps for all EMS Admin, EMS User, ADJ Admin, ADJ User and ICC accounts needed to satisfy the county infrastructure needs. 3.3.2.11 Changing User Passwords on the EMS Standard Server The County will need to change their Windows passwords from the default. The passwords for numbered emsadmin, emsuser and iccadmin accounts must match on the workstation and the server. To change the password for the local Admin Account (EMSADMIN): 1. Log in as the EMSAdmin or Admin User. 2. Press Ctrl+Alt+Delete. 3. Select Change a Password… 4. Enter the old and new the password and confirm it. 6/18/2024 42 Version: 5.19::4 Chapter 3 - System Installation and Configuration 5. Click the arrow. To change the password for server client authentication accounts (EMS Standard Server): 1. Right-click on the Windows icon and then select Computer Management. 2. Expand Local Users and Groups. 3. Select Users. 4. Right-click on the user account and select Set Password… 5. Click Proceed. 6. Set the new password, and then click OK. 7. After changing all necessary passwords, restart the computer. 3.3.2.12 Applying Cepstral Licenses on the EMS Standard Server Required: Cepstral license key for county (Cepstral) To apply Cepstral licenses on the EMS Standard Server: 1. Click the Windows Start button, and then click Cepstral Speech Tools. 2. When prompted by the UAC, click Yes. 3. Click the Activation Keys tab, and then click Advanced. 4. Select the appropriate voice from the drop-down menu that displays. 5. Input the county's licensing key information, making sure that the Company and Name fields match exactly what is in the license information. 6. Click Submit. When prompted to confirm the action, click OK. 7. Repeat steps 3 to 6 for each additional voice license that the county has purchased. 8. Under the Personal Use Activation Key section, input the Save to file license information. NOTE: Do not enter information for the port activation license key. 9. After entering all of the keys, click OK to close the window. 3.3.2.13 Verifying Time Zone, Date and Time (EMS Standard Server) Required: Smartphone (or other trusted time source) To verify the time zone, date and time on the EMS Standard Server: 1. Sign in to the EMS Standard Server. 6/18/2024 43 Version: 5.19::4 Chapter 3 - System Installation and Configuration 2. Select Start > Settings The Settings window appears. 3. Select Time & Language. 4. Ensure Set time automatically and Set time zone automatically is set to OFF. 5. Verify that the time zone is correct. a. If necessary, adjust the time zone by typing ‘timedate.cpl’ in the search bar and then selecting running as Administrator. 6. Ensure auto-adjustment for Daylight Saving Time is set to ON. 7. Verify that the current date and time are correct. To adjust the date and time: a. Click Change. The Change date and time window displays. b. Enter the correct date and time, and then click Change. 8. Close the Settings window. 3.3.2.14 Rerunning the Data Center Manager (EMS Standard Server) As part of the added security in this release it is critical to ensure that the Data Center Manager (DCM) is run post image deployment. This will generate a county specific encryption key that is used to secure the databases. 1. Navigate to the file DemocracySuiteEMS_DCM.exe and then right-click and select Run as Administrator. 2. When prompted by the UAC window, click Yes. The DCM window will open. NOTE: If you receive a warning about Adjudication, close the window and ensure that the previous steps have been completed. Otherwise, continue on to the next steps. 3. From the Configuration Type drop-down menu, select Remove All Certificates. 4. Click Next. 5. Leave all the default paths and click Next. 6. Once the application has completed its scan of the system, click Apply Setting. 7. When prompted, click OK to restart the server, and then repeat Steps 1 through 6. 8. From the Configuration Type drop-down menu, select Certificates Installation. 9. Click Next. 6/18/2024 44 Version: 5.19::4 Chapter 3 - System Installation and Configuration 10. Leave all the default paths and click Next. 11. Once the application has completed its scan of the system, click Apply Setting. 12. When prompted, click OK to restart the server. 3.3.2.15 Downloading and Applying Windows Defender Updates To download and apply Windows Defender updates on the EMS Standard Server: 1. From a computer with Internet access, navigate to the following link: https://www.microsoft.com/en-us/wdsi/definitions 2. Locate the latest Defender Anti-Virus updates for Windows Server 64-bit version, and download the update file. 3. Copy the downloaded defender update file (mpam-fe.exe) to a secured and scanned USB removable medium. 4. Insert the USB removable medium into the Windows Server workstation, and then double-click the update file. 5. Restart the Server. 6. To verify that the updates have been applied, click the Windows Start button, and then click the Windows Security icon pinned to the Start menu. 7. Click Virus & Threat Protection. 8. Under the Virus & threat protection updates section, verify that the last update corresponds to the current date. 3.3.2.16 Exporting the Adjudication Client Certificate from the Local Machine Certificate Store NOTE: If you will not be using Adjudication, skip this section. To export the Adjudication Client Certificate from the Local Machine Certificate Store on the EMS Standard Server: 1. Press Start and type Manage computer certificates. 2. Press Enter. The certlm window displays. 3. From the navigation menu, select Personal > Certificates. 4. Right-click the Adjudication Client Certificate and select All Tasks > Export. The Certificate Export Wizard displays. 5. Click Next. The Export Private Key page displays. 6/18/2024 45 Version: 5.19::4 Chapter 3 - System Installation and Configuration 6. Select Yes, export the private key and click Next. The Export File Format page displays. 7. Select Personal Information Exchange - PKCS #12 (.PFX) and Export all extended properties. 8. Click Next. The Security page displays. 9. Select Password. 10. In the Password field, enter a password for the certificate. 11. In the Confirm password field, re-enter the password. 12. Click Next. The File to Export page displays. 13. Click Browse... and save the file with the name Adjudication Client Certificate. The Completing the Certificate Export Wizard page displays. 14. Click Finish. The Certificate Export Wizard dialog displays. 15. Click OK. 16. If you will be using Adjudication on an EMS Client Workstation, transfer the exported Adjudication Client Certificate to removable USB media. 3.3.2.17 Importing the Adjudication Client Certificate to the Current User Certificate Store NOTE: If you will not be using Adjudication, skip this section. After you have successfully exported the Adjudication Client Certificate from the Local Machine Certificate Store on the EMS Standard Server, you need to import the certificate to the User Certificate Store on the machine that will be running Adjudication. If you will be using Adjudication on an EMS Client workstation, refer to the Democracy Suite® EMS Client Workstation Installation and Configuration Procedure, "Importing the Adjudication Client Certificate to the Current User Certificate Store". If you will be using Adjudication on the EMS Standard Server, complete the following procedure: 1. On the EMS Standard Server locate and double-click the exported Adjudication Client Certificate. The Certificate window displays. 2. Click Install Certificate.... The Certificate Import Wizard displays. 6/18/2024 46 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3. Select Current User and click Next. The File to Import page displays. 4. Click Next. The Private key protection page displays. 5. In the Password field, enter the password you created when you exported the certificate. 6. Select Mark this key as exportable. This will allow you to back up or transport your keys at a later time and Include all extended properties. 7. Click Next. The Certificate Store page displays. 8. Select Place all certificates in the following store. 9. Click Browse... The Select Certificate Store dialog displays. 10. Select Personal and click OK. 11. Click Next. The Completing the Certificate Import Wizard page displays. 12. Click Finish. The Certificate Import Wizard dialog displays. 13. Click OK. To access the Adjudication application, open Microsoft Edge and navigate to the following URL: https://'machinename'/ADJApplication/#/login. In the Select a certificate dialog, select the Adjudication Client Certificate and then click OK. The Adjudication login screen displays. 3.3.2.18 Applying Hardening (EMS Standard Server) To apply hardening on the EMS Standard Server: 1. Right-click the EMS Security Hardening Application (SHA) from the task bar, and then select RUN AS ADMINISTRATOR. 2. When prompted by the User Account Control window, click Yes. 3. Select the Protection option from the left-side pane. 4. Verify that Standalone is listed in the drop-down menu at the top, and then click Harden this Machine. 5. When prompted to confirm the action, click Yes. 6. From the Confirm system restart window, click Yes. 7. Once the server has restarted, open the application, and confirm that the system is now hardened. 6/18/2024 47 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.3.2.19 Applying Post Hardening BIOS Settings (EMS Standard Server) The following describes the configuration steps for applying post-hardening BIOS and iDRAC settings on the EMS Standard Server: 1. During boot, press F2 when the prompts appear at top of the screen, the Entering-System Setup option is highlighted in blue; the system will enter the System Setup menu after devices have been initialized. 2. Enter the BIOS Set-up password when prompted. 3. In the System Setup main menu, click System BIOS. 4. Click Network Settings, set all PXE devices to Disabled, and then click Back. 5. Click Boot Settings, and select UEFI Boot Settings. 6. Verify that only Integrated RAID CONTROLLER 1: Windows Boot Manager is checked. Click Back and then Back again to return to the System BIOS menu screen. 7. Click System Security, enable Secure Boot, and then click Back. 8. If a setup password was not required to change BIOS settings, click System Security, enter a strong password into the Setup Password field, and then click OK. 9. Re-enter the password, and then click Back. 10. Click Finish. Confirm the changes by clicking Yes and then OK. 11. From the System Setup screen, click iDRAC Settings. 12. Click Network from the iDRAC Settings menu. 13. Under the Network Settings menu, set Enable NIC to Enabled. 14. Scroll down and verify that the following settings are set to Disabled: a. Common Settings: Disabled b. IPV4 Settings: Disabled c. IPV6 Settings: Disabled 15. Click Finish to exit back to the System Setup screen. 16. From the System Setup screen, click Finish, and then Yes to confirm. 3.3.3 Upgrading the EMS Client Workstation This section describes how to upgrade the EMS Client Workstation from version 5.10-A to version 5.19. 6/18/2024 48 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.3.3.1 EMS Client Workstation Checklist The following checklist (Table 3-2) provides a quick reference to the steps that must be performed when upgrading the county's EMS Client workstations. No. Item Complete 1. Disconnect from network switch 2. Configure BIOS 3. Deploy Golden Image 4. Update BIOS 5. Removing Unused Accounts 6. Activate Windows 11 7. Set the correct Time Zone 8. Verify Drivers in Device Manager 9. Rename Workstation (if necessary) 10. Connect to network switch 11. Configure Report Printer 12. Apply latest Windows Defender Updates 13. Adjusting Autoplay Settings 14. Install Server Certificate 15. Apply BitLocker Encryption (if being used) 16. Apply Hardening 17. Apply Post Hardening BIOS Settings 18. Acceptance Test Table 3-2: EMS Workstation Checklist 3.3.3.2 Configuring the BIOS Settings on the EMS Client Workstation BIOS settings may already be set, but they should be reset to default and reconfigured to ensure they are correct and consistent. 6/18/2024 49 Version: 5.19::4 Chapter 3 - System Installation and Configuration NOTE: Depending on the client model, the BIOS interface may look different. Counties systems should have a previously set BIOS password (Admin password). This password will need to be entered when attempting to change BIOS settings and when booting from the Acronis removable media. Configuring BIOS Settings for the Dell Precision 3450/3460 1. During system startup, press F2 to enter the Setup menu. 2. In the Setup menu, click Admin Password Unlock if password protected. 3. Enter the Admin password if prompted, and then click OK. 4. Click Load Defaults. 5. Select BIOS defaults, and click OK. Click OK to load all system settings. 6. Click OK to restart the system. 7. During system startup, press F2 to re-enter the Setup menu. 8. In the Setup menu, click Admin Password Unlock if available, enter the Admin password if prompted, and then click OK. 9. Verify/set the following settings: BIOS List Item Option To Be Set • Delete the Onboard NIC (IPV4) Option Boot Configuration • Delete the Onboard NIC (IPV6) Option • Boot Sequence • Delete the UEFI HTTPs Boot Option Boot Configuration • Secure Boot Set “Enable Secure Boot” to ON Integrated Devices • Serial Port Set to “Disabled” Storage • SATA Operation Check the “AHCI” radio button Storage • SMART REPORTING Enable Smart Reporting Table 3-3: BIOS Settings Options - Dell Precision 3450/3460 6/18/2024 50 Version: 5.19::4 Chapter 3 - System Installation and Configuration BIOS List Item Option To Be Set Connection • Network Controller Configuration Set the Integrated NIC to “Enabled” Connection • Uncheck WLAN • Wireless Device Enable • Uncheck Bluetooth Connection • HTTP(s) Boot Feature Set to “Disabled” Table 3-3: BIOS Settings Options - Dell Precision 3450/3460 10. Click Apply, and then click Exit to reboot the computer. 3.3.3.3 Deploying Image (Windows 11 Computers) Required: Acronis 2023N bootable media, SSD with golden images To deploy golden images on the EMS Client Workstation (using Windows 11 Computers): 1. Copy the Acronis backup image to an external hard disk. 2. Insert the Acronis bootable removable media device and external hard disk into the machine to be restored. 3. Power on/restart the computer. 4. Press F12. 5. Select the Acronis bootable removable media device. 6. In section Recovery, select Browse for Backup... 7. Browse to the local folder location of the external hard disk where the image was copied, and then click OK. 8. From the Archive Name section, select the appropriate file (e.g., ‘Backup #1’). 9. Right-click the selected backup file and click Recover. 10. Select Recover Whole disks and partitions from recovery methods. 11. Select the recovery point of the chosen image. 12. From the What to recover screen that displays, select Disks, and then select Disk 1. 13. From the destination of selected disks (see Step 12), select the disks from where the backups need to be recovered. 6/18/2024 51 Version: 5.19::4 Chapter 3 - System Installation and Configuration 14. Click Proceed. The image restoration process initiates. 15. Once the Acronis restore is complete, restart the workstation, and then safely eject the removable media device and external hard disk. NOTE: When the workstation is booted for the first time after restoring the image, it may take some time for Windows to initialize the devices. This is normal. Wait until the initialization process is complete. 3.3.3.4 Updating BIOS (Windows 11 Computers) To update the BIOS settings for the EMS Client Workstation using Windows 11 computers: 1. Open the folder on the Desktop labeled BIOS UPDATE. 2. Double-click the BIOS update executable. NOTE: Ensure that the BIOS update is for the model being restored. 3. When prompted by the UAC window, click Yes. A prompt will appear describing the update. 4. Click OK. 5. Click OK to start the update. The update will begin. 6. When prompted, click Restart to reboot the computer. DO NOT turn off the PC. 7. Once rebooted, delete the BIOS UPDATE folder from the Desktop and empty the Recycle Bin. 3.3.3.5 Removing Unused Accounts (EMS Client Workstation) The workstation image was created with preconfigured user accounts that match the server. Depending on the county infrastructure, preconfigured accounts will need to be removed or additional accounts added accordingly. To remove unused user accounts: 1. Log into the correct Administrator account for the workstation being deployed (i.e., EMS Workstation 3 would be EMSADMIN03 etc.). 2. Right-click on the Windows icon and then select Computer Management. 3. Expand Local Users and Groups. 4. Select Users. 5. Right-click on the user account that DOES NOT correspond to the workstation being deployed and select Delete. 6/18/2024 52 Version: 5.19::4 Chapter 3 - System Installation and Configuration 6. Click Yes. 7. Repeat steps 5 and 6 for all user accounts that do not correspond to the workstation being deployed 8. Restart the workstation. 3.3.3.6 Activating Windows Required: Smartphone activation link To activate Windows on the EMS Client Workstation: 1. Type 'SLUI 3' and then press Enter. 2. Type the machine's product key and click Next. 3. Click Activate, and then click Close. 4. Type 'SLUI 4' and press Enter. 5. Select region: United States. Click Next. You should see the installation ID to use for activation. This will be 9 sets of 7 digits. To activate Windows by phone: 1. Call the number from your phone (855-801-0109). 2. Use the following responses to get to the phone activation system or follow the prompts: a. "Do you consent to this call being recorded?" Press 2 (No) b. When prompted, repeat the security phrase. c. When prompted, say "activate Windows". d. "Are you at your computer with the window open?" Say "Yes". e. When asked if you would like a link sent to the Smartphone, say "Yes". f. Once you have the link, hang up. 3. Open the link and select Windows, and then Windows 11. 4. Enter the code from the screen, click Submit. 5. Enter the response code from the link into the Activation window on the computer. 3.3.3.7 Verifying and Installing System Drivers in Device Manager If deploying the image onto a different workstation model, system drivers will need to be updated. To verify and install system drivers in Device Manager: 1. Click the Windows icon button, and then click Device Manager. 6/18/2024 53 Version: 5.19::4 Chapter 3 - System Installation and Configuration 2. Verify that there are no yellow exclamation marks displayed next to the any device. 3. If all devices clear verification, close the Device Manager. Otherwise, if drivers need to be updated, proceed to step 4. 4. Insert the removable medium containing the CAB driver files as part of the upgrade kit. 5. Right-click on the device that requires updating and then click Update Driver. 6. Select Browse my Computer for Drivers. 7. Browse to the USB removable medium containing the CAB files, select the computer model CAB, and then click OK. 8. Click Next. Windows will install the appropriate driver for the device. 9. Once the install process successfully completes, click Close. 10. Repeat Steps 5 through 9 as needed. 11. Close the Device Manager once complete. 3.3.3.8 Setting the Correct Time Zone To set the correct time zone on the EMS Client Workstation: 1. Right-click the clock in the lower-right corner, select Adjust Date and Time. 2. Select the correct time zone from the Time Zone drop-down menu. 3. Close the Date and Time window. 3.3.3.9 Changing the Computer Name (EMS Client, ADJ Client, and ICC Client) Required: County Infrastructure Document You should only change the computer name for the EMS Client Workstation if necessary. To change the computer name: 1. Right-click on the Windows Start button, and then select System. 2. From the System window, click Rename this PC (advanced). 3. Click Change. 6/18/2024 54 Version: 5.19::4 Chapter 3 - System Installation and Configuration 4. Change the computer name as necessary. For EMS Client, ADJ Client and ICC machines that are not the first of that computer type, change the name so that the number of the machine matches the number on the computer's label (see Example 1 and 2 below). Refer to the county's infrastructure document for the correct name(s). Example 1: For the computer labeled "EMSCLIENT01," the machine name should already be set to EMSCLIENT01 and does not need to be changed. Example 2: For the computer labeled "EMSCLIENT02," the machine name should be set to EMSCLIENT02. 5. Windows will prompt you to reboot. Accept the prompt to reboot the computer. If no changes have been made to the computer name, you can proceed to the next section without rebooting. 3.3.3.10 Connecting Computers to the Network Switch (EMS Client, ADJ Client, ICC) After computers have been renamed (if necessary) and rebooted, connect them to the network switch. 3.3.3.11 Downloading and Applying Windows Defender Updates To download and apply Windows Defender Updates on the EMS Client Workstation: 1. From a computer with Internet access, navigate to the following link: https://www.microsoft.com/en-us/wdsi/definitions 2. Locate the latest Defender Anti-Virus updates for Windows Server 64-bit version, and download the corresponding update file. 3. Copy the downloaded Defender update file (mpam-fe.exe) to a secured and scanned USB removable medium. 4. Insert the USB removable medium into the Windows Server workstation, then locate and double-click on the update file. The update begins. 5. When prompted that the update is complete, restart the workstation. 6. To verify that the updates have been applied, click the Windows Defender shield icon in the taskbar. 7. Click Virus & Threat Protection. 8. Under the Virus & Threat Protection Updates section, verify that the last update corresponds to the current date. 6/18/2024 55 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.3.3.12 Adjusting Autoplay Settings To adjust Autoplay settings on the EMS Client Workstation: 1. In the workstation search bar, type “Autoplay Settings” and then select Autoplay Settings. 2. From the Autoplay Settings window, under the Removable Drive drop- down, select Take No Action. 3. From the Autoplay Settings window, under the Memory Card drop-down menu, select Take No Action. 4. Close the Settings window. 3.3.3.13 Installing Trusted Server Certificate To install a trusted server certificate on the EMS Client Workstation: 1. Navigate to the NAS on the server via the mapped drive. 2. Open the Common folder. 3. Double-click the DVS Implementation Root.crt. 4. Click Install Certificate. 5. Select Local Machine. 6. If prompted with a UAC window, click Yes. 7. Check the Place all certificates in the following store option. 8. Click Browse, select Trusted Root Certification Authorities, and then click OK. 9. Click Next. 10. Click Finish. 3.3.3.14 Applying BitLocker Encryption (EMS Client Workstation) If BitLocker encryption will be used, please refer to Appendix L“Bitlocker Encryption” for steps to enable the encryption. 3.3.3.15 Applying Hardening (EMS Client Workstation) To apply hardening on the EMS Client Workstation: 1. Click the Windows Start button, right-click the EMS Security Hardening Application (SHA), and select RUN AS ADMINISTRATOR. 2. When prompted by the User Account Control window, click Yes. 3. Select the Protection option from the left-side pane. 6/18/2024 56 Version: 5.19::4 Chapter 3 - System Installation and Configuration 4. Verify that Client Workstation is listed in the drop-down at the top, and then select Harden this Machine. 5. When prompted to confirm, click Yes. 6. From the Confirm System Restart window, click Yes. The server will restart. 7. Once the server has restarted, open the SHA application, and confirm that the system is now hardened. 3.3.3.16 Configuring Post Hardening BIOS (EMS Client Workstation) To configure post hardening BIOS settings for Dell Precision 3440. 3450, and 3460 models: 1. During system boot, press F2 to enter the Setup menu. 2. In the Setup menu, click Unlock and enter the Admin password if prompted. 3. Click Integrated Devices, scroll down to USB Configuration, and uncheck Enable USB Boot Support. 4. If no Admin BIOS Password was configured, click Passwords. 5. Enter a password for the BIOS ADMIN, and then press Enter. Re-enter the password and click Enter to confirm. 6. Click Apply Changes, and when prompted click OK to confirm. 7. Click Exit to reboot. 3.3.4 Upgrading the Adjudication Client Workstation This section describes how to upgrade the Adjudication Client Workstation from version 5.10-A to version 5.19. 3.3.4.1 Adjudication Client Workstation Checklist The following checklist (Table 3-7) provides a quick reference to the steps that must be performed when upgrading the county's computer systems. No. Item Complete 1. Disconnect from network switch 2. Confgure BIOS 3. Deploy Golden Image 4. Update BIOS Table 3-4: Application Workstation 6/18/2024 57 Version: 5.19::4 Chapter 3 - System Installation and Configuration No. Item Complete 5. Apply Post Imaging BIOS configuration 6. Activate Windows 11 7. Verify Drivers in Device Manager 8. Set Screen Orientation if necessary 9. Add/Remove User Accounts 10. Rename Workstation if necessary 11. Connect to network switch 12. Configure Report Printer 13. Apply latest Windows Defender Updates 14. Apply Hardening 15. Reset regional time settings 16. Acceptance Test Table 3-4: Application Workstation 3.3.4.2 Configuring the BIOS on Windows 11 Adjudication Workstation The BIOS settings may already be set. Regardless, you should reset them to default and reconfigure them to ensure they are correct and consistent. NOTE: Depending on the client model, the BIOS interface may look different. Counties systems should have a previously set BIOS password (Admin password). This password will need to be entered when attempting to change BIOS settings and when booting from the Acronis USB. Configuring the Initial BIOS on the EMS Adjudication Workstation To initially configure the BIOS: 1. During the workstation’s startup, press F2 to enter the Setup menu. 2. In the Setup menu, click Unlock if it is password protected. 3. Enter the Admin password if prompted. 4. Click Restore Settings or Load Defaults. 5. Select BIOS defaults and click OK. 6. Click OK to load all system settings. 6/18/2024 58 Version: 5.19::4 Chapter 3 - System Installation and Configuration 7. After the settings have been restored, restart the workstati0n, by clicking Exit at the menu. 8. During the restart, press F2 to enter the Setup menu 9. In the Setup menu, click Unlock if available. 10. Enter the Admin password if prompted. 11. Verify/set the following General settings: a. Boot Sequence: Boot List Option: Set to UEFI b. Advanced boot options: Clear the Enable Legacy Option ROMs checkbox (disabled), if available 12. Verify/set the following System Configuration settings: a. SATA operation: Set to AHCI b. SMART reporting: Selected (enabled) c. USB Configuration: Enable USB Boot Support: Selected d. Secure Boot: Selected (enabled e. Wireless: Disable all Wireless options (Bluetooth, WLAN/WiGig) 13. Click Apply then click OK. 14. Click Exit to restart the workstation. 3.3.4.3 Deploying the Image on the Adjudication Workstation The following items are required for this procedure: • Acronis 2023N bootable media • SSD with golden images NOTE: Before deploying the image, confirm that you have applied all the required BIOS settings. To deploy the image: 1. Copy the Acronis backup image to an external hard disk. 2. Insert the Acronis bootable removable media device and external hard disk into the machine to be restored. 3. Power on/restart the Workstation. 4. Press F12. 5. Select the Acronis bootable removable media device. 6. In section Recovery, select Browse for Backup... 7. Browse to the local folder location of the external hard disk where the image was copied, and then click OK. 6/18/2024 59 Version: 5.19::4 Chapter 3 - System Installation and Configuration 8. From the Archive Name section, select the appropriate file (e.g., ‘Backup #1’). 9. Right-click the selected backup file and click Recover. 10. Select Recover Whole disks and partitions from recovery methods. 11. Select the recovery point of the chosen image. 12. From the What to recover screen that displays, select Disks, and then select Disk 1. 13. From the destination of selected disks (see Step 12), select the disks from where the backups need to be recovered. 14. Click Proceed. The image restoration process initiates. 15. Once the Acronis restore is complete, restart the workstation, and then safely eject the removable media device and external hard disk. 3.3.4.4 Updating BIOS (Windows 11 Computers) To update the BIOS settings for the EMS Adjudication Workstation using Windows 11 computers: 1. Open the folder on the Desktop labeled BIOS UPDATE. 2. Double-click the BIOS update executable. NOTE: Ensure that the BIOS update is for the model being restored. 3. When prompted by the UAC window, click Yes. A prompt will appear describing the update. 4. Click OK. 5. Click OK to start the update. The update will begin. 6. When prompted, click Restart to reboot the computer. DO NOT turn off the PC. 7. Once rebooted, delete the BIOS UPDATE folder from the Desktop and empty the Recycle Bin. 3.3.4.5 Configuring the Post Image Deployment BIOS on the EMS Adjudication Workstation To configure the BIOS, post image deployment : 1. During the workstation’s startup, press F2 to enter the Setup menu. 2. In the Setup menu, click Unlock if available. 3. Enter the Admin password if prompted. 6/18/2024 60 Version: 5.19::4 Chapter 3 - System Installation and Configuration 4. Click Boot Settings > Boot Sequence. 5. Disable all boot options that will not be used. 6. Click System Configuration. 7. Select USB Configuration and clear the USB Boot Support checkbox. 8. Click OK, then click Yes to confirm. 3.3.4.6 Activating Windows 11 on the EMS Adjudication Workstation The following items are required for this procedure: • Smartphone • Activation link To activate Windows 11: 1. Type SLUI 3 and press Enter. 2. Type the machine's product key and click Next. 3. Click Activate then click Close. 4. Type SLUI 4 and press Enter. 5. Select the region to United States. 6. Click Next. You should see the installation ID to use for activation. This will be 9 sets of 7 digits. 3.3.4.7 Removing Unused Accounts (EMS Adjudication Workstation) The workstation image was created with preconfigured user accounts that match the server. Depending on the county infrastructure, preconfigured accounts will need to be removed or additional accounts added accordingly. To remove unused user accounts on the Adjudication Client Workstation: 1. Log into the correct user account for the workstation being deployed (i.e. ADJCLIENT03 would be ADJADMIN03, etc.) 2. Right-click on the Windows icon and then select Computer Management. 3. Expand Local Users and Groups. 4. Select Users. 5. Right-click on the user account that DOES NOT correspond to the workstation being deployed and select Delete. 6. Click Yes. 6/18/2024 61 Version: 5.19::4 Chapter 3 - System Installation and Configuration 7. Repeat steps 5 and 6 for all user accounts that do not correspond to the workstation being deployed. 8. Restart the workstation. 3.3.4.8 Updating the Windows Registry NOTE: If you are not using Adjudication, skip this section. During the server installation, EMS Data Center Manager (DCM) created a registry file (.reg) named ADJCertMapper in the NAS folder. To avoid having to manually select the Adjudication Client Certificate each time you open the Adjudication client application, you need to use ADJCertMapper to update the Windows Registry on the EMS Client workstation. To update the Windows Registry: 1. On the EMS Server, navigate to C:\NAS\Common and copy ADJCertMapper to removable USB media. 2. Eject the USB media from the EMS Server and connect it to the EMS Client Workstation. 3. Transfer ADJCertMapper to the EMS Client workstation desktop. 4. On the desktop, double-click ADJCertMapper. A User Account Control dialog displays. 5. Click Yes. The Registry Editor warning dialog displays. 6. Click Yes. The Registry Editor success dialog displays. 7. Click OK. 3.3.4.9 Clearing the Cache in Microsoft Edge and Accessing the Adjudication Application NOTE: If you are not using Adjudication, skip this section. After updating the Windows Registry, you then need to clear the cache in Microsoft Edge. To do so, follow these steps: 1. Press Start and type Microsoft Edge. 2. Press Enter. Microsoft Edge opens. 3. Press Alt + F. 4. From the menu, select Settings. 5. From the navigation menu, select Privacy, search, and services. 6/18/2024 62 Version: 5.19::4 Chapter 3 - System Installation and Configuration 6. In the Clear browsing data section, next to Clear browsing data now, click Choose what to clear. The Clear browsing data dialog displays. 7. From the Time range drop-down, select All time. 8. Click Clear now. The cache is cleared. To access the Adjudication application, open Microsoft Edge and navigate to the following URL: https://'machinename'/ADJApplication/#/login. In the Select a certificate dialog, select the Adjudication Client Certificate and click OK. The Adjudication login screen displays. The next time you open Adjudication, the Select a certificate dialog will not display. 3.3.4.10 Creating an Adjudication Desktop Shortcut Microsoft Edge allows you to install a webpage as a standalone app, creating a shortcut on your desktop for easy access. If you install Adjudication as an app, you will not need to open Microsoft Edge and enter the URL each time you want to open Adjudication. To install Adjudication as an app: 1. Press Start and type Microsoft Edge. 2. Press Enter. Microsoft Edge opens. 3. Navigate to the following URL: https://'machinename'/ADJApplication/#/ login. 4. Press Alt + F. 5. From the menu, select Apps > Install this site as an app. The Install app dialog displays. 6. Click Install. The Adjudication window opens and the App installed dialog displays. 7. Select Create Desktop shortcut. 8. Click Allow. Adjudication is now installed as an app with a shortcut on your desktop. To launch Adjudication, double-click the desktop shortcut. 6/18/2024 63 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.3.4.11 Verifying and Installing System Drivers in Device Manager on the Adjudication Workstation If you are deploying the image onto a different workstation model, you will need to update the system drivers. To verify and install system drivers: 1. At the desktop, click the Windows button then click Device Manager. 2. Verify there are no yellow exclamation marks next to any device. 3. If all devices are healthy, close Device Manager and proceed to “Set Screen Orientation (ADJ Client)”. 4. If drivers need to be updated, insert the USB media containing the CAB driver files as part of the upgrade kit. 5. Right-click the device that requires updating and click Update Driver. 6. Click Browse my Computer for Drivers. 7. Browse to the USB media containing the CAB files, select the computer model CAB, the click OK. 8. Click Next. Windows installs the appropriate driver for the device. 9. Click Close when the install successfully finishes. 10. Repeat steps 5 through 9 as needed. 11. Close Device Manager once complete. 3.3.4.12 Set Screen Orientation (ADJ Client) If you plan to use Adjudication in Portrait Mode, you will need to set the screen orientation appropriately. Otherwise, proceed to the next section. 1. Right-click on the desktop and select Display Settings. 2. Under Orientation, select Portrait. 3. Click Keep Changes. 6/18/2024 64 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.3.4.13 Importing the Adjudication Client Certificate to the Current User NOTE: If you are not using Adjudication, skip this section. If you will be using Adjudication on the EMS Client workstation, you need to import the Adjudication Client Certificate to the Current User Certificate Store. For information about exporting the Adjudication Client Certificate from the EMS Server, refer to Democracy Suite® EMS Standard Installation and Configuration Procedure. To import the Adjudication Client Certificate: 1. Connect the USB media containing the Adjudication Client Certificate to the EMS Client workstation. 2. Transfer the certificate to the EMS Client workstation. 3. On the EMS Client workstation, locate and double-click the exported Adjudication Client Certificate. The Certificate window displays. 4. Click Install Certificate.... The Certificate Import Wizard displays. 5. Select Current User and click Next. The File to Import page displays. 6. Click Next. The Private key protection page displays. 7. In the Password field, enter the password you created when you exported the certificate. 8. Select Mark this key as exportable. This will allow you to back up or transport your keys at a later time and include all extended properties. 9. Click Next. The Certificate Store page displays. 10. Select Place all certificates in the following store. 11. Click Browse.... The Select Certificate Store dialog displays. 12. Select Personal and click OK. 13. Click Next. The Completing the Certificate Import Wizard page displays. 14. Click Finish. The Certificate Import Wizard dialog displays. 15. Click OK. 6/18/2024 65 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.3.4.14 Applying BitLocker Encryption (Adjudication Client Workstation) If BitLocker encryption will be used, please refer to Appendix L“Bitlocker Encryption” for steps to enable the encryption. 3.3.4.15 Changing the Computer Name on the Adjudication Workstation To change the Adjudication workstation’s computer name: 1. At the desktop, click the Windows icon, then click Control Panel > System. 2. Click Rename this PC (advanced). 3. Click Change. 4. Verify that the Workgroup is set to EMS.NET 5. Change the computer name as necessary: • For an EMS Client workstation that is not the first of that computer type, change the name so that the number of the machine matches the number on the workstation’s label. Refer to the county's infrastructure document for the correct name(s). • Example 1: for the workstation labeled "ADJCLIENT01," the computer name should already be set to ADJCLIENT01 and does not need to be changed. • Example 2: for the workstation labeled "ADJCLIENT02," the computer name should be set to ADJCLIENT02. Windows will prompt you to restart the workstation. 6. If changes have been made to the computer name, accept the prompt to restart the workstation. 7. If no changes have been made to the computer name, proceed to section 3.3.4.16“Connecting the EMS Adjudication Workstation to the Network Switch” without accepting the prompt. 3.3.4.16 Connecting the EMS Adjudication Workstation to the Network Switch After the computers have been renamed (if necessary) and rebooted, connect them to the network switch. 3.3.4.17 Configuring the Report Printer for the EMS Adjudication Workstation To configure the report printer for the EMS Adjudication Workstation: 1. Locate the print driver for the report printer to be used. 6/18/2024 66 Version: 5.19::4 Chapter 3 - System Installation and Configuration 2. Run the driver executable to install the driver. 3. Once complete, plug in the report printer and verify it has been added. 4. Click Control Panel from the taskbar, then click Devices and Printers. 5. Select the report printer from the list of devices. 6. Print a test page and click Finish. 7. If the report printer is not set as default, right-click on it while you still have the Devices and Printers window open, and then click Set as Default. 3.3.4.18 Downloading and Applying Windows Defender Updates for the EMS Adjudication Workstation To download and apply Windows Defender updates for the Adjudication Workstation: 1. From a computer with Internet access, navigate to the following link: https:/ /www.microsoft.com/en-us/wdsi/definitions 2. Locate the latest Defender Anti-Virus updates for Windows 11, download the update file. 3. Copy the downloaded defender update file (mpam-fe.exe) to a secured and scanned USB. 4. Insert the USB into the EMS Client workstation and double-click the update file. 5. Restart the EMS Client workstation. 6. To verify that the updates have been applied, click the windows defender shield icon in the taskbar. 7. Click Virus & Threat Protection. 8. Under the Virus & threat protection updates section, verify that the last update was the current date. 3.3.4.19 Applying Hardening to the EMS Adjudication Workstation To harden the EMS Adjudication Workstation: 1. Click the Windows icon, from the start pane, right-click EMS Security Hardening Application and select Run As Administator. 2. If prompted by the User Account Control window, click Yes. 3. Select the Protection option from the left-side pane. 4. Select the appropriate option from the dropdown list depending on the type of system to be hardened. Click Harden this Machine. 5. When prompted to confirm, click Yes. 6. From the Confirm system restart window, click Yes. 6/18/2024 67 Version: 5.19::4 Chapter 3 - System Installation and Configuration 7. Once the system has restarted the user may confirm that the hardening completed successfully by opening the application again and clicking Protection > Verify Hardening. 3.3.4.20 Resetting Regional Date/Time Settings on the EMS Adjudication Workstation The hardening scripts set the date and time display to an incorrect format. The date and time format should be reset to default. Perform these steps only after you have rebooted the computer and run the hardening scripts. 1. Click Control Panel from the taskbar. 2. Under View By in the top right on this screen, select Small Icons. 3. Click Region. 4. Click Additional Settings. 5. Click Reset. 6. Click Yes. 7. Click OK. 8. Click OK. 9. Close the open dialogs. 3.3.5 Upgrading the ImageCast Voter Activation Workstation This section describes how to upgrade the ImageCast Voter Activation (ICVA) Workstation from version 5.10-A to version 5.19. 3.3.5.1 ICVA Workstation Checklist The following checklist (see Table3-5) provides a quick reference to the steps that ® must be performed when upgrading the county’s ImageCast Voter Activation computer systems. No. Item Complete 1. Configure BIOS 2. Deploy Golden Image 3. Update BIOS 4. Activate Windows 11 5. Verify Drivers in Device Manager 6/18/2024 68 Version: 5.19::4 Chapter 3 - System Installation and Configuration No. Item Complete 6. Rename Workstation (if necessary) 7. Configure Report Printer 8. Apply latest Windows Defender Updates 9. Apply Hardening 10. Apply Post Hardening BIOS Settings 11. Acceptance Test Table 3-5: ICVA Workstation Checklist 3.3.5.2 Configuring the BIOS on the ICVA Workstation The BIOS settings may already be set. Regardless, you should reset them to default and reconfigure them to ensure that they are correct and consistent. County systems should have a previously set BIOS password (Admin password). You need to enter this password when attempting to change BIOS settings and when booting from the Acronis USB. 1. During system startup, press F2 to enter the Setup menu. 2. In the Setup menu, click Unlock if available. 3. Enter the Admin password if prompted. 4. Click Restore Settings or Load Defaults. 5. Select BIOS defaults, click OK, and click OK to load all system settings. 6. After settings have been restored, reboot the computer by clicking Exit. 7. During system startup, press F2 to re-enter the Setup menu. 8. In the Setup menu, click Unlock if available. 9. Enter the Admin password if prompted. 10. Verify / Set the following settings: • System Configuration: • Date and Time: Set current date and time • Enable SMART reporting: ON (enabled) • USB Configuration: Enable USB Boot Support is ON • SATA operation: AHCI • Boot mode: UEFI • Secure boot: 6/18/2024 69 Version: 5.19::4 Chapter 3 - System Installation and Configuration • Enable Secure Boot: ON (enabled) • Wireless: Disable all options • Disable onboard devices that will not be used (e.g., camera, microphone etc.) 11. Click Apply, and then click OK. 12. Click Exit to reboot the computer. 3.3.5.3 Deploying the Image on the ICVA Workstation Before deploying the image on the ICVA Workstation, ensure that you have the following prerequisites: • Acronis 2023N bootable media • SSD with golden images Before deploying the image, verify that all BIOS settings have been applied. Start with the ICVA workstation powered off. 1. Copy the Acronis backup image to an external hard disk. 2. Insert the Acronis bootable removable media device and external hard disk into the machine to be restored. 3. Power on the workstation. 4. Press F12. 5. Select the Acronis bootable removable media device. 6. In section Recovery, select Browse for Backup... 7. Browse to the local folder location of the external hard disk where the image was copied, and then click OK. 8. From the Archive Name section, select the appropriate file (e.g., ‘Backup #1’). 9. Right-click the selected backup file and click Recover. 10. Select Recover Whole disks and partitions from recovery methods. 11. Select the recovery point of the chosen image. 12. From the What to recover screen that displays, select Disks, and then select Disk 1. 13. From the destination of selected disks (see Step 12), select the disks from where the backups need to be recovered. 14. Click Proceed. The image restoration process initiates. 15. Once the Acronis restore is complete, restart the workstation, and then safely eject the removable media device and external hard disk. 6/18/2024 70 Version: 5.19::4 Chapter 3 - System Installation and Configuration NOTE: When the workstation is booted for the first time after restoring the image, it may take some time for Windows to initialize the devices. This is normal. Wait until the initialization process is complete. 3.3.5.4 Updating BIOS (Windows 11 Computers) To update the BIOS settings for the ICVA Workstation using Windows 11 computers: 1. Open the folder on the Desktop labeled BIOS UPDATE. 2. Double-click the BIOS update executable. NOTE: Ensure that the BIOS update is for the model being restored. 3. When prompted by the UAC window, click Yes. A prompt will appear describing the update. 4. Click OK. 5. Click OK to start the update. The update will begin. 6. When prompted, click Restart to reboot the computer. DO NOT turn off the PC. 7. Once rebooted, delete the BIOS UPDATE folder from the Desktop and empty the Recycle Bin. 3.3.5.5 Activating Windows on the ICVA Workstation The following items are required for this procedure: • Smartphone • Activation link To activate Windows 11: 1. At the Windows Start menu, type CMD. 2. Right-click the option for CMD and click Run As Administrator. 3. At the command prompt, type wmic path softwarelicensingservice get OA3xOriginalProductKey and press Enter. 4. Take note of the product key. 5. Type ‘SLUI 3’ and press Enter. 6. Type the machine's product key and then click Next. 7. Click Activate and then click Close. 8. Type ‘SLUI 4’ and press Enter. 9. Select the region to United States. 6/18/2024 71 Version: 5.19::4 Chapter 3 - System Installation and Configuration 10. Click Next. You should see the installation ID to use for activation. This will be 9 sets of 7 digits. To activate Windows 11 by phone: 1. Call the number from your phone (855-801-0109). 2. Use the following responses to get to the phone activation system or follow the prompts: a. “Do you consent to this call being recorded?” Press 2 (No) b. When prompted, repeat the security phrase. c. When prompted, say “activate Windows”. d. “Are you at your computer with the window open?” Say “Yes”. e. When asked if you would like a link sent to the Smartphone, say “Yes”. f. Once you have the link, hang up. 3. Open the link and select Windows, and then Windows 11. 4. Enter the code from the screen, click Submit. 5. Enter the response code from the link into the Activation window on the computer. 6. Once complete, close all windows. 3.3.5.6 Verifying and Installing System Drivers in Device Manager on the ICVA Workstation If you are deploying the image onto a different workstation model, you will need to update the system drivers. To verify and install system drivers: 1. At the desktop, click the Windows button, then click Device Manager. 2. Verify there are no yellow exclamation marks next to any device. 3. If all devices clear verification, close Device Manager. If drivers need to be updated, proceed to step 4: 4. Insert the USB removable media containing the CAB driver files as part of the upgrade kit. 5. Right-click the device that requires updating and click Update Driver. 6. Click Browse my Computer for Drivers. 7. Browse to the USB removable media containing the CAB files, select the computer model CAB, and then click OK. 6/18/2024 72 Version: 5.19::4 Chapter 3 - System Installation and Configuration 8. Click Next. Windows installs the appropriate driver for the device. 9. Click Close when the install successfully finishes. 10. Repeat steps 5 through 9 as needed. 11. Close Device Manager once complete. 3.3.5.7 Updating the BIOS on the ICVA Workstation To update the BIOS on the ICVA Workstation: 1. Open the folder on the desktop labeled BIOS UPDATE. 2. Double-click on the BIOS update executable. NOTE: Ensure that the BIOS update is for the model being restored. 3. Click Yes if prompted by UAC. A prompt appears describing the update. 4. Click OK. 5. Click OK to start the update. The update begins. 6. When prompted, click Restart to reboot the computer. The workstation restarts while updating. DO NOT turn off the workstation. 7. Once rebooted, delete the BIOS UPDATE folder, and empty the Recycle Bin. 3.3.5.8 Changing the Computer Name on the ICVA Client Workstation Before changing the computer name on the ICVA workstation, ensure that you have the following prerequisites: • County Infrastructure Document To change the computer name: 1. Click Start, click Control Panel, and then click System. 2. Click Rename this PC (advanced). 3. Click Change. 4. Change the computer name as necessary: • For MBP Client that are not the first of that computer type, change the name so that the number of the machine matches the number on the computer’s label. Refer to the county’s infrastructure document for the correct name(s). • Example 1: For the computer labeled "ICVACLIENT01," the machine name should already be set to ICVACLIENT01 and does not need to be changed. 6/18/2024 73 Version: 5.19::4 Chapter 3 - System Installation and Configuration 5. Windows will prompt you to reboot. Accept the prompt to reboot the computer. If no changes have been made to the computer name, you can proceed to the next section without rebooting. 3.3.5.9 Configuring the Report Printer for the ICVA Workstation To configure the report printer for the ICVA Workstation: 1. Locate the print driver for the report printer to be used. 2. Run the driver executable to install the driver. 3. Once complete, plug in the report printer and verify it has been added. 4. Click Control Panel from the taskbar, then click Devices and Printers. 5. Select the report printer from the list of devices. 6. Print a test page and click Finish. 7. If the report printer is not set as default, right-click on it while you still have the Devices and Printers window open and click Set as Default. 3.3.5.10 Downloading and Applying Windows Defender Updates for the ICVA Workstation To download and apply Windows Defender updates for the ICVA Workstation: 1. From a computer with Internet access, navigate to the following link: https:/ /www.microsoft.com/en-us/wdsi/definitions 2. Locate the latest Defender Anti-Virus updates for Windows 11, download the update file. 3. Copy the downloaded defender update file (mpam-fe.exe) to a secured and scanned USB medium. 4. Insert the USB medium into the ICVA workstation and double-click the update file. 5. Restart the ICVA workstation. 6. To verify that the updates have been applied, click the Windows Defender shield icon in the taskbar. 7. Click Virus & Threat Protection. 8. Under the Virus & threat protection updates section, verify that the last update corresponds to the current date. 3.3.5.11 Applying BitLocker Encryption (ICVA Workstation) If BitLocker encryption will be used, please refer to Appendix L“Bitlocker Encryption” for steps to enable the encryption. 6/18/2024 74 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.3.5.12 Applying Hardening to the ICVA Workstation To harden the ICVA Workstation: 1. Click Start, right-click EMS Security Hardening Application and select Run As Administrator. 2. If prompted by the User Account Control window, click Yes. 3. Select the Protection option from the left-side pane. 4. Select the appropriate option from the drop-down list depending on the type of system to be hardened. Click Harden this Machine. 5. When prompted to confirm, click Yes. 6. From the Confirm system restart window, click Yes. 7. Once the system has restarted the user may confirm that the hardening completed successfully by opening the application again and clicking Protection > Verify Hardening. 3.3.5.13 Configuring the Post Hardening BIOS on the ICVA Workstation To configure the post image deployment BIOS on the ICVA workstation: 1. During boot, press F2 to enter the Setup menu. 2. In the Setup menu, click Unlock if available. 3. Enter the Admin password if prompted 4. Click Boot Settings > Boot Sequence and disable all boot options that will not be used. 5. Click System Configuration > USB Configuration and uncheck USB Boot Support. 6. Click OK, and click Yes to confirm. 3.3.5.14 Resetting Regional Date/Time Settings on the ICVA Workstation The hardening scripts set the date and time display to an incorrect format. The date and time format should be reset to default. Perform these steps only after you have rebooted the computer, after the hardening scripts have been run. 1. Click Control Panel from the taskbar. 2. Under View By in the top right on this screen, select Small Icons. 3. Click Region. 4. Click Additional Settings. 6/18/2024 75 Version: 5.19::4 Chapter 3 - System Installation and Configuration 5. Click Reset. 6. Click Yes. 7. Click Ok. 8. Click Ok. 9. Close the open dialogs. 3.3.6 Upgrading the ImageCast Central Client Workstation This section describes how to upgrade the ImageCast Central (ICC) Workstation from version 5.10-A to version 5.19. 3.3.6.1 ICC Client Workstation Checklist The following checklist (see Table3-6) provides a quick reference to the steps that must be performed when upgrading the county’s computer systems. No. Item Complete 1. Configure BIOS 2. Deploy Golden Image 2. Update BIOS 3. Activate Windows 11 4. Remove Unused User Accounts 5. Set Correct Time Zone 6. Verify Drivers in Device Manager 7. Rename Workstation if necessary 8. Connect to network switch 9. Configure Report Printer 10. Apply latest Windows Defender Updates 11. Scanner Firmware Update and Front Panel Settings 12. Verify time zone, date, and time (if standalone) 13. Apply Hardening 14. Apply Post Hardening BIOS Settings 15. Acceptance Test 6/18/2024 76 Version: 5.19::4 Chapter 3 - System Installation and Configuration Table 3-6: ICC Client Workstation checklist 3.3.6.2 Configuring the BIOS on the ICC Client Workstation The BIOS settings may already be set, but they should be reset to default and reconfigured to ensure they are correct and consistent. NOTE: Depending on the client model, the BIOS interface may look different. Counties systems should have a previously set BIOS password (Admin password). This password will need to be entered when attempting to change BIOS settings and when booting from the Acronis removable media device. Initial BIOS Configuration for Dell Precision 3440 To initially configure the BIOS for the Dell Precision 3440: 1. During the workstation’s startup, press F2 to enter the Setup menu. 2. In the Setup menu, click Unlock if it is password protected. 3. Enter the Admin password if prompted. Click OK. 4. Click Restore Settings, select BIOS defaults, and click OK. 5. Click OK to load all system settings. 6. After the settings have been restored, restart the workstation by clicking Exit at the menu. 7. During the restart, press F2 to re-enter the Setup menu. 8. In the Setup menu, click Unlock if available and enter the Admin password if prompted. 9. Verify/set the following General settings: BIOS List Item Option To Be Set General • Uncheck Onboard NIC (IPV4) • Boot Sequence • Uncheck Onboard NIC (IPV6) System Configuration • Integrated NIC Set to “Enabled” System Configuration • Serial Port Set to “Disabled” Table 3-7: BIOS Settings Options - Dell Precision 3440 6/18/2024 77 Version: 5.19::4 Chapter 3 - System Installation and Configuration BIOS List Item Option To Be Set System Configuration • SATA Operation Check the “AHCI” radio button System Configuration • SMART REPORTING Enable Smart Reporting Secure Boot • Secure Boot Enable Check “Secure Boot Enable” Wireless • Uncheck WLAN/WiGig • Wireless Device Enable • Uncheck Bluetooth Table 3-7: BIOS Settings Options - Dell Precision 3440 10. Click Apply and then click OK. 11. Click Exit to restart the workstation. BIOS Configuration for Dell Precision 3450/3460 To configure BIOS settings for Dell Precision 3450/3460: 1. During the workstation’s startup, press F2 to enter the Setup menu. 2. In the Setup menu, click Admin Password Unlock if it is password protected. 3. Enter the Admin password if prompted. Click OK. 4. Click Load Defaults. 5. Select BIOS defaults and click OK. 6. Click OK to load all system settings. 7. Click OK to restart the system. 8. During restart, press F2 to re-enter the Setup menu. 6/18/2024 78 Version: 5.19::4 Chapter 3 - System Installation and Configuration 9. In the Setup menu, click Admin Password Unlock if available, enter the Admin password if prompted, and then click OK. BIOS List Item Option To Be Set • Delete the Onboard NIC (IPV4) Option Boot Configuration • Delete the Onboard NIC (IPV6) Option • Boot Sequence • Delete the UEFI HTTPs Boot Option Boot Configuration • Secure Boot Set “Enable Secure Boot” to ON Integrated Devices • Serial Port Set to “Disabled” Storage • SATA Operation Check the “AHCI” radio button Storage • SMART REPORTING Enable Smart Reporting Connection • Network Controller Configuration Set the Integrated NIC to “Enabled” Connection • Uncheck WLAN • Wireless Device Enable • Uncheck Bluetooth Connection • HTTP(s) Boot Feature Set to “Disabled” Table 3-8: BIOS Settings Options - Dell Precision 3450/3460 10. Click Apply, and then click Exit to reboot the computer. BIOS Configuration for Dell Optiplex 7440/3050/5270 To configure BIOS settings for Dell Optiplex 7440/3050/5270: 1. During the workstation’s startup, press F2 to enter the Setup menu. 2. In the Setup menu, click Admin Password Unlock if it is password protected. 3. Enter the Admin password if prompted. Click OK. 4. Click Load Defaults. 6/18/2024 79 Version: 5.19::4 Chapter 3 - System Installation and Configuration 5. Select BIOS defaults and click OK. 6. Click OK to load all system settings. 7. Click OK to restart the system. 8. During restart, press F2 to re-enter the Setup menu. 9. In the Setup menu, click Unlock if available, enter the Admin password if prompted, and then click OK. 10. Verify/set the following settings: BIOS List Item Option To Be Set General • Boot Sequence UEFI radio button is Checked General • Advanced Boot Options Uncheck “Enable Legacy Option ROMs” System Configuration • Integrated NIC Set to “Enabled” System Configuration • Serial Port Set to “Disabled” System Configuration • SATA Operation Check the “AHCI” radio button System Configuration • SMART REPORTING Enable Smart Reporting Secure Boot • Secure Boot Enable Check “Secure Boot Enable” Wireless • Uncheck WLAN/WiGig • Wireless Device Enable • Uncheck Bluetooth Table 3-9: BIOS Settings Options - Dell Optiplex 7440/3050/5270 11. Click Apply, and then click Exit to reboot the computer. 3.3.6.3 Deploying the Image on the ICC Client Workstation (Windows 11 Computers) The following items are required for this procedure: 6/18/2024 80 Version: 5.19::4 Chapter 3 - System Installation and Configuration • Acronis 2023N bootable media • SSD with golden images NOTE: Before deploying the image verify all BIOS settings have been applied. To deploy the image: 1. Copy the Acronis backup image to an external hard disk. 2. Insert the Acronis bootable removable media device and external hard disk into the machine to be restored. 3. Power on/restart the Workstation. 4. Press F12. 5. Select the Acronis bootable removable media device. 6. In section Recovery, select Browse for Backup... 7. Browse to the local folder location of the external hard disk where the image was copied, and then click OK. 8. From the Archive Name section, select the appropriate file (e.g., ‘Backup #1’). 9. Right-click the selected backup file and click Recover. 10. Select Recover Whole disks and partitions from recovery methods. 11. Select the recovery point of the chosen image. 12. From the What to recover screen that displays, select Disks, and then select Disk 1. 13. From the destination of selected disks (see Step 12), select the disks from where the backups need to be recovered. 14. Click Proceed. The image restoration process initiates. 15. Once the Acronis restore is complete, restart the workstation, and then safely eject the removable media device and external hard disk. NOTE: When the workstation is booted for the first time after restoring the image, it may take some time for Windows to initialize the devices. This is normal. Wait until the initialization process is complete. 3.3.6.4 Updating BIOS (Windows 11 Computers) To update the BIOS settings for the ICC Client Workstation using Windows 11 computers: 1. Open the folder on the Desktop labeled BIOS UPDATE. 2. Double-click the BIOS update executable. 6/18/2024 81 Version: 5.19::4 Chapter 3 - System Installation and Configuration NOTE: Ensure that the BIOS update is for the model being restored. 3. When prompted by the UAC window, click Yes. A prompt will appear describing the update. 4. Click OK. 5. Click OK to start the update. The update will begin. 6. When prompted, click Restart to reboot the computer. DO NOT turn off the PC. 7. Once rebooted, delete the BIOS UPDATE folder from the Desktop and empty the Recycle Bin. 3.3.6.5 Activating Windows on the ICC Client Workstation The following items are required for this procedure: • Smartphone • Activation link To activate Windows: 1. At the Windows Start menu, type CMD. 2. Right-click the option for CMD and click Run As Administrator. 3. At the command prompt, type wmic path softwarelicensingservice get OA3xOriginalProductKey and press Enter. 4. Take note of the product key (for Windows 11 Computers). 5. Type ‘SLUI 3’ and press Enter. 6. Type the machine's product key and click Next. 7. Click Activate then click Close. 8. Type ‘SLUI 4’ and press Enter. 9. Set the region to United States. 10. Click Next. You should see the installation ID to use for activation. This will be 9 sets of 7 digits. To activate Windows by phone: 1. Call the number from your phone (855-801-0109). 2. Use these responses to get to the phone activation system or follow the prompts: a. “Do you consent to this call being recorded?” Press 2 (No) b. When prompted, repeat the security phrase. 6/18/2024 82 Version: 5.19::4 Chapter 3 - System Installation and Configuration c. When prompted, say “Activate windows”. d. “Are you at your computer with the window open?” Say “Yes”. e. When asked if you would like a link sent to the Smartphone, say “Yes”. 3. Once you have the link, hang up. 4. Open the link and select Windows, then Windows 11. 5. Enter the code from the screen, and then click Submit. 6. Enter the response code from the link into the activation window on the computer. 7. Once complete, close all windows. 3.3.6.6 Removing Unused User Accounts on the ICC Client Workstation The workstation image was created with preconfigured user accounts. Depending on the county infrastructure, preconfigured accounts will need to be removed or additional accounts added accordingly. To remove unused user accounts on the ICC Client Workstation: 1. Log into the correct user account for the workstation being deployed (i.e. ICCCLIENT03 would be ICCADMIN03, etc.) 2. Right-click on the Windows icon and then select Computer Management. 3. Expand Local Users and Groups. 4. Select Users. 5. Right-click on the user account that DOES NOT correspond to the workstation being deployed and select Delete. 6. Click Yes. 7. Repeat steps 5 and 6 for all user accounts that do not correspond to the workstation being deployed 8. Restart the workstation. 3.3.6.7 Setting the Correct Time Zone To set the correct time zone on the ICC Client Workstation: 1. Right-click the clock in the lower-right corner, select Adjust Date and Time. 2. Select the correct time zone from the Time Zone drop-down menu. 3. Close the Date and Time window. 6/18/2024 83 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.3.6.8 Verifying and Installing System Drivers in Device Manager If deploying the image onto a different workstation model, system drivers will need to be updated. To verify and install system drivers in Device Manager: 1. Click the Windows icon button, and then click Device Manager. 2. Verify that there are no yellow exclamation marks displayed next to the any device. 3. If all devices clear verification, close the Device Manager. If drivers need to be updated, proceed to step 4: 4. Insert the removable medium containing the CAB driver files as part of the upgrade kit. 5. Right-click on the device that requires updating and then click Update Driver. 6. Select Browse my Computer for Drivers. 7. Browse to the USB removable medium containing the CAB files, select the computer model CAB, and then click OK. 8. Click Next. Windows will install the appropriate driver for the device. 9. Once the install process successfully completes, click Close. 10. Repeat Steps 5 through 9 as needed. 11. Close the Device Manager once complete. 3.3.6.9 Changing Computer Name (ICC Client) Required: County Infrastructure Document You should only change the computer name for the ICC Client Workstation if necessary. To change the computer name: 1. Right-click on the Windows Start button, and then select System. 2. From the System window, click Rename this PC (advanced). 3. Click Change. 6/18/2024 84 Version: 5.19::4 Chapter 3 - System Installation and Configuration 4. Change the computer name as necessary. For EMS Client, ADJ Client and ICC machines that are not the first of that computer type, change the name so that the number of the machine matches the number on the computer's label (see Example 1 and 2 below). Refer to the county's infrastructure document for the correct name(s). Example 1: For the computer labeled "ICCCLIENT01," the machine name should already be set to ICC01 and does not need to be changed. Example 2: For the computer labeled "ICCCLIENT02," the machine name should be set to ICCCLIENT02. 5. Windows will prompt you to reboot. Accept the prompt to reboot the computer. If no changes have been made to the computer name, you can proceed to the next section without rebooting. 3.3.6.10 Connecting Computers to the Network Switch (ICC Client Workstation) After computers have been renamed (if necessary) and rebooted, connect them to the network switch. 3.3.6.11 Downloading and Applying Windows Defender Updates 1. From a computer with Internet access, navigate to the following link: https:/ /www.microsoft.com/en-us/wdsi/definitions 2. Locate the latest Defender Anti-Virus updates for Windows 11, download the update file. 3. Copy the downloaded defender update file (mpam-fe.exe) to a secured and scanned USB medium. 4. Insert the USB medium into the ICC Client workstation and double-click the update file. 5. Restart the ICC Client workstation. 6. To verify that the updates have been applied, click the Windows Defender shield icon in the taskbar. 7. Click Virus & Threat Protection. 8. Under the Virus & threat protection updates section, verify that the last update corresponds to the current date. 3.3.6.12 Updating Canon Scanner Firmware (ICC Workstation with DRG2140 scanners) If you have one of the following Canon scanners, you may need to update the firmware: 6/18/2024 85 Version: 5.19::4 Chapter 3 - System Installation and Configuration • DR-G2140 NOTE: The firmware installer is located on the C:\ Drive of the ICC workstation. The Canon scanners should be updated to the following firmware versions: • DR-G2140: 1.43 Before updating the scanner firmware, ensure you have the following prerequisites: • iButton for test project • Election files for test project To update the scanner firmware: 1. Navigate to the ICC Drivers folder located on the C:\ Drive of the ICC workstation and select the appropriate scanner model. 2. Run the firmware update executable. 3. Accept the prompts to install the firmware. Each module takes a few minutes to install. The entire process takes about 5 minutes. 4. After the firmware has been updated, power off the scanner and power it on again. NOTE: Do not allow the computer to be turned off or the scanner to lose power during the update process. This will disable the scanner. 3.3.6.13 Configuring the Canon Scanner Front Panel Settings This section describes how to configure the Canon DR-G2140 front panel settings. Configuring the DR-G2140 Scanners This section will explain how to configure the DR-G2140 scanner panel settings in two parts. Only perform these steps after the firmware update has been completed (if firmware update is necessary). Step 1: 1. On the ICC workstation, click Start. 2. Under the C group click Canon DR G2000 Series and select Canon imageFORMULA Driver Setting Tool. User Account Control appears. 3. Click Yes. 4. Click the Control tab. 5. Under Hardware, click Settings. 6/18/2024 86 Version: 5.19::4 Chapter 3 - System Installation and Configuration 6. Under Power Management, clear Turn off automatically after 4 hours. 7. Click the Settings Change Method tab. 8. Set Long Document Mode to on PC, and then click Apply. 9. Restart the scanner. 10. Once the scanner has restarted, returning to the imageFORMULA tool, set Long Document Mode to on Scanner Panel. 11. Click Apply, click OK, and then click Close. 12. Restart the scanner. Step 2: Front Panel Settings: 1. On the scanner, press Menu. 2. On the front panel of the G2140 scanner, press the down arrow button to select Scan Setting, and then press the OK button. 3. Press the down arrow button to select Long Document, and then press the OK button. 4. Select Max Document Length, and then press the OK button. 5. Press the down arrow button to select Long Document (1000mm), and then press the OK button. 6. Press the Menu button. 7. Press the up arrow button to select Scanner Setting, and then press the OK button. 8. Press the down arrow button to select Auto Power Off, and then press the OK button. 9. Select Off, and then press the OK button. 10. Press the Menu button. 11. Press the Job Select button. 3.3.6.14 Verifying Time Zone, Date, and Time on the ICC Client Workstation (for Standalone ICC) Before beginning this task, ensure you have the following prerequisites: • Smartphone (or other trusted time source) To check the time zone, date, and time on the ICC Client Workstation: 1. Right-click and select Adjust date/time. 6/18/2024 87 Version: 5.19::4 Chapter 3 - System Installation and Configuration 2. Ensure that Set time automatically and Set time zone automatically are switched ON. 3. Verify that the time zone is UTC-05:00, Eastern Time, US & Canada. 4. Adjust the time zone if necessary, by selecting it from the drop-down menu. 5. Ensure auto-adjustment for daylight saving time is switched ON. 6. Close the Settings window. 3.3.6.15 Applying Hardening on the ICC Client Workstation To apply hardening on the ICC Client Workstation: 1. Click Start, right-click EMS Security Hardening Application and select Run As Administrator. 2. If prompted by the User Account Control window, click Yes. 3. Select the Protection option from the left-side pane. 4. Select the appropriate option from the drop-down list depending on the type of system to be hardened. Click Harden this Machine. 5. When prompted to confirm, click Yes. 6. From the Confirm system restart window, click Yes. 7. Once the system has restarted the user may confirm that the hardening completed successfully by opening the application again and clicking Protection > Verify Hardening. 3.3.6.16 Post Hardening BIOS (ICC Client Workstation) Post Hardening BIOS for Dell Precision 3440, 3450 and 3460 models To configure post hardening BIOS for Dell Precision 3440, 3450 and 3460 models: 1. During system startup, press F2 to enter the Setup menu. 2. In the Setup menu, click Unlock, and enter the Admin password if prompted. 3. Click Integrated Devices, scroll down to USB Configuration, and uncheck Enable USB Boot Support. 4. If no Admin BIOS Password was configured, click Passwords. 5. Enter a password for the BIOS ADMIN, and then press Enter. Re-enter the password and click Enter to confirm. 6. Click Apply Changes. 7. When prompted, click OK to confirm. 6/18/2024 88 Version: 5.19::4 Chapter 3 - System Installation and Configuration 8. Click Exit to restart the system. Post Hardening BIOS for Dell Optiplex 7440/3050/5270 To configure post hardening BIOS for Dell Optiplex 7440/3050/5270: 1. During system startup, press F2 to enter the Setup menu. 2. In the Setup menu, click Unlock, and enter the Admin password if prompted. 3. Click Boot Settings, select Boot Sequence, and disable all boot options that will not be used. 4. Expand System Configuration, select USB Configuration, and uncheck USB Boot Support. 5. If no Admin BIOS Password was configured, click Security. 6. Enter a password for the BIOS ADMIN, re-enter the password to confirm it, and then click OK. 7. Click Apply Changes. 8. When prompted, click Yes to confirm. 9. Click Exit to restart the system. 3.4 Software Installation and Configuration Software installation is completed through image deployment. However, once images are deployed to the client workstations, additional configuration may be required. This section includes configuration procedures for all components. NOTE: For detailed installation and configuration instructions, please see the ® Democracy Suite EMS Client Workstation Installation and Configuration Procedure document. 3.4.1 EMS Configuration The EMS system consists of different components that work together to cover the pre-voting and post-voting activity workflows. The configuration of EMS components has to do with the following: 1. Specifics of how to define and configure an Election Project in the EED application, MBS/DCF/MCF configuration and access to RTR application (see 3.4.1.1“Election Project Configuration in EED”). 2. Configuration of the Adjudication application (see 3.4.2“Adjudication Configuration” and the RTR application (see 3.4.3“RTR Configuration”). 6/18/2024 89 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.4.1.1 Election Project Configuration in EED If your project is programmed by the Dominion Voting, then the project you receive will already be created and configured as specified in this use procedure. However, if you are programming your own elections, then ensure that the following are true: ® 1. The names of all ImageCast Central tabulators are prefixed with the word "ICC" (see D.2.1.5“Defining Tabulators”). 2. The MBS and DCF files are set to agreed values if values other than the ® default are required (see appendix A“ImageCast Central 2 Machine ® Behavior Settings” and appendix B“ImageCast Evolution and ® ImageCast Precinct 2 Machine Behavioral Settings”). 3. Ensure that Activation Codes in EED are named so that they may be easily distinguished between each other when loaded to the ICVA application. 4. If the project has more languages than those automatically provided by the EMS system, the audio folders for such languages need to be manually created on the Election Definition EMS Server by the EMS Administrator (see 12.2.6“Setting up Project for Additional Audio Languages”). 5. Create and activate the RTR Administrative user in EMS EED. Note the User Name and Password for the RTR Administrator (see 12.2.7“Creation of RTR User in Election Event Designer”). 3.4.1.2 Configuring EED for Additional Language Packs EED can be configured to use additional languages for static display information and audio files when creating ICE, ICP2 and ICX election projects. Configuring EED for Additional ICE and ICP2 Language Packs This procedure requires access and possession of the additional language packs desiredto the following: • {LanguageName}.qm file(s) • Static audio files (.spx) • AudioFiles.xml To configure EED to use additional ICE and ICP2 language packs: 1. At the EMS Standard Server, insert media containing required language packs. 2. Save the.qm translation source files to: D:\NAS\Common\Resources\Imagecast_Evolution\enc\Translat ions 6/18/2024 90 Version: 5.19::4 Chapter 3 - System Installation and Configuration • Example: D:\NAS\ Common\Resources\Imagecast_Evolution\enc\Translations\Arabic.qm Figure 3-4: Adding a language pack 3. Save the folder containing static audio files (*.spx) to: D:\NAS\Common\Resources\Imagecast_Evolution\sig\Audio\st atic\ • Example: D:\NAS\Common\Resources\Imagecast_Evolution\sig\Audio\static\A rabic 4. Save the folder containing the Audio configuration file (AudioFiles.xml) to: D:\NAS\Common\Resources\Imagecast_Evolution\enc\Configu ration\Arabic In EED, a new ICE or ICP2 election project can now be created and configured with language copied in the above steps. ICE and ICP2 static display information and audio files for respective language(s) will take effect. NOTE: If the project is already in the Ready for Elections stage, roll back the project to the Ballots Generated stage and move forward to Ready for Elections. To roll back the project: 1. In EED go to Settings > Election Event Properties. 2. From the Election Project Status drop down menu, select Ballots Generated. 3. Click OK. 4. In the dialog box that appears, click Continue. 5. Click Actions > Tabulation > Create Election Files. 6. In the dialog box that appears, click Continue. 7. Another dialog box may appear stating that election files will be recreated, click Continue. 6/18/2024 91 Version: 5.19::4 Chapter 3 - System Installation and Configuration ICE/ICP2 cards programmed with EED will have the resources in the directories specified below. NOTE: ‘X’ denotes the drive letter assigned by Windows Operating System to SD/ CF card inserted. • .qm files: X:\resources\Translations • Static Audio files: X:\resources\Audio\Static\ • Audio configuration: X:\resources\Configuration NOTE: Enable corresponding voter languages in the ICE and ICP2 MBS for the new language to appear in. Configuring EED for Additional ICX Language Packs This procedure requires access and possession of the additional language packs desired to the following: • Localization JSON file • Static audio files (folder with Language abbreviation containing all static audio instructions) • Language Name recording (language name recording file) To configure EED to use additional ICX language packs: 1. On the EMS Standard Server, insert media containing required language packs. 2. Save the JSON file to: D:\NAS\Common\Resources\ImageCast_X\localizations • Example: D:\NAS\Common\Resources\ImageCast_X\localizations\yue_12_local izations.json Ignore the.dsfx file if not available. 6/18/2024 92 Version: 5.19::4 Chapter 3 - System Installation and Configuration Figure 3-5: Adding Localization File 3. Repeat Step 1 for all applicable localization files. 4. Save the folder with the language abbreviation containing Static audio files to: D:\NAS\Common\Resources\ImageCast_X\staticaudio\ • Example: D:\NAS\Common\Resources\ImageCast_X\staticaudio\yue 6/18/2024 93 Version: 5.19::4 Chapter 3 - System Installation and Configuration Figure 3-6: Adding Static Audio Folder 5. Save the Language name audio file to: D:\NAS\Common\Resources\ImageCast_X\staticaudio\language s\ • Example: D:\NAS\Common\Resources\ImageCast_X\staticaudio\languages\yue. spx 6/18/2024 94 Version: 5.19::4 Chapter 3 - System Installation and Configuration Figure 3-7: Adding Language Audio File 6. Repeat Step 3 and 4 for all applicable Static audio folder and language files. NOTE: If the election project being configured has no AVS support, step 3 and 4 can be skipped. In EED, new ICX election projects can now be created and configured with language(s) copied according to the above steps. ICX static display information and audio files for respective language(s) will take effect. NOTE: If the project is already in the “Ready for Elections” stage, roll back the project to the “Ballots Generated” stage and move forward to “Ready for Elections”. To roll back the project: 1. In EED go to Settings > Election Event Properties. 2. From the Election Project Status drop-down menu, select Ballots Generated. 3. Click OK. 4. In the dialog box that appears, click Continue. 5. Click Actions > Tabulation > Create Election Files. 6. In the dialog box that appears, click Continue. 6/18/2024 95 Version: 5.19::4 Chapter 3 - System Installation and Configuration 7. Another dialog box may appear stating that election files will be recreated, click Continue. The ISO code field in the EED Language Profile window (see Fig 3-8“EED Language Profile window” below) must match the localization file prefix and the name of the Static audio folder copied in Steps 1 and 2. If necessary, revise the value in the ISO code field to match the values from Steps 1 and 2. Figure 3-8: EED Language Profile window 3.4.2 Adjudication Configuration Set adjudication outstack conditions and perform adjudication on the batches sent to the application (see Chapter 9“Adjudication” for more details). 6/18/2024 96 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.4.3 RTR Configuration The RTR application should be configured to automatically receive results from adjudication (see 8.1.2“Open Project” and 8.2.3“Automatic Result Loading”). 3.4.4 ImageCast® Central System Configuration ® Depending on the specifics of the Democracy Suite installation, there might be one or more ICC workstations present in the system configuration. The ICC system can work in two modes described below. 1. ICC system used in isolation of the EMS system, where network connectivity does not exist. In this case, the results and images are stored in the specified directory on the local workstation (refer to 7.5"Configuring the Secondary or Server Path for Saving Results”). The results are then transferred, using the removable memory media, and saved to the RTR workstation. Then, such results are loaded into the RTR via Load Results from Directory (refer to 8.2.2"Load Results from Directory”) functionality or results may be loaded by placing them in the folder defined for automatic results loading. 2. ICC system used in a networked configuration, where one or more ICC workstations are connected to the EMS Server via a network switch. In this scenario, the ICC system can be configured to save the copy of results and images directly to the Results folder on the NAS drive on the EMS Server (see 7.5“Configuring the Secondary or Server Path for Saving Results”). If the jurisdiction uses RTR to automatically load results, then see Configuring the Local and Remote Path for Saving Results (refer to 7.5"Configuring the Secondary or Server Path for Saving Results”). If automatic loading of results is not required, or local only saving of results is preferred, then the Secondary Path can be left undefined. 6/18/2024 97 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.4.4.1 InterScan HiPro Scanner Hardware Configuration The following table provides a checklist to be used to confirm the ICC’s HiPro scanner hardware configuration. Scanner Hardware Input Tray Input tray extension (19”) with angle to be used for ballots longer 14”. Hexagonal Pre-Input Roller to be equipped with green riffled linings Separation Roller with higher resistance (10.3 Ncm) to be used with default white linings. The pressure of the separation roller should be increased by 4 turns of the knob The pressure of the Pre-Input roller should be set to a middle position initially.In case of basic feed-in issues the pressure can be increased. Output Tray The High-Speed Stacker Arm must to be equipped with the jam sensor extension. The front plate should be tightened with a M3x6mm screw together with a washer DIN9021 to prevent movement of the extension arm. Use Distance Sensor instead of the Hopper Plate Sensor. If double feeds are ejected to the Rear Output, a longer tray must be equipped for longer ballots to prevent rear output jams or the use of a large box to collect ballots. Ensure ballots are collected for rescan after every batch. Calibrations White Calibration should be done once between installing/ cleaning the scanner unit and the starting of a tabulation process. Area Stop This should be set to inches with a value of 11.8. Table 3-10: Scanner Hardware 6/18/2024 98 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.4.5 ImageCast® Evolution Configuration ® ® Democracy Suite EMS allows for the programming of specific ImageCast Evolution tabulators for use in office early voting or in vote centers. Ballot tabulation for a specific precinct, a range of precincts, or all of the precincts in the election may be programmed. Depending on the consolidation type selected in the election project, the number of ballots that is created for an election could be very large. This number will depend on a number of factors, including: number of precincts, number of languages and number of elector group combinations. For the early vote ICE tabulators, care needs to be taken with regards to how many precincts are assigned to each of those tabulators, in case when the number of ballots is very large. It is recommended that early vote ICE tabulators be assigned no more than 4000 ballot styles, and no more than 1000 precincts. If new ICE language fonts are required for the display, please contact your Dominion Voting representative who will walk you through updating the configuration file (MBS) that allows for the installation of new fonts and reverting back to the original configuration file. 3.4.5.1CF0 Card Data Partitioning As part of the ICE election verification process at start-up, the data is copied from the CF1 card to the CF0 card. If your election project is 800 MB or greater, the project may be too large for the tabulator’s CF0 card. Performing this procedure will increase the size of the CF0 card’s available data partition to 4 GB. The vhd image (GApplication.vhd) is used to re-image the CF0 card resulting in the increase of available data partition on the CF0 card. For this process, you complete the following: • Identify the CF0 Card’s Current Data Partition Size • Increase the CF0 Card’s Date Partition Size Identifying the CF0 Card’s Current Data Partition Size To determine whether the partition increase is necessary, you should identify the CF0 card’s current partition size. NOTE: This procedure assumes the tabulator’s firmware version is 5.19 To identify the CF0 card’s current partition size: 1. Power up the tabulator. Once tabulator boots up, various messages regarding unexpected conditions detected might be displayed. 2. Press Next to view each message. 6/18/2024 99 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3. Press OK at the final message. 4. When the message “Startup error” appears, disregard. 5. Log into the Technician Menu: a. Apply the ICE Technician Key. b. Enter the credentials. 6. From the Technician Menu, press Diagnostics. 7. From the Diagnostics screen. press System Status. 8. From the System Status screen, go to the CF Status section. 9. Review the value in the System card data partition field. NOTE: The System card data partition value refers to the CF0 card’s partition size. If the partition size (including the free space) is 1 GB or less, re-image the CF0 card using the procedure described in Increase the CF0 Card’s Partition Size. However, if the partition size is over 3000 MB, there is no need to continue with this procedure. Increasing the CF0 Card’s Partition Size If the CF0 card’s data partition size is 1 GB or less, re-image the card to increase the partition size. NOTE: This procedure assumes the following: • Tabulator’s firmware version is 1.0 • Access to a PC with Internet connection To increase the CF0 card’s data partition size, you will need to complete the following: • Remove the CF0 Card from the Tabulator • Prepare the PC • Reimage the CF0 Card • Reinstall the CF0 Card into the Tabulator • Confirm the CF0 Card’s New Data Partition Size To Remove the CF0 Card from the Tabulator: 1. If the tabulator is on, power it down. 2. On the right side of the tabulator, open the CF1 and CF2 doors. 3. Using a T20 Security Bit screwdriver, remove the two screws from the metal plate covering the CF0 card slot. 4. To eject the CF0 card, push the button to the right of the card. 6/18/2024 100 Version: 5.19::4 Chapter 3 - System Installation and Configuration 5. Remove the card from the tabulator’s slot. To Prepare the PC: 1. At a PC with an internet connection, go to http://www.winimage.com/ download.htm. 2. Download winima90.exe. WinImage is installed. 3. Go to the ICE 1.0 release folder on the DVD provided by DVS and copy the GApplication 7.zip to the PC with the winima90.exe file. 4. Extract all files to the PC’s local folder. 5. Connect the CF reader/writer to the same PC. 6. Insert the CF0 card recently removed from the tabulator, into the CF reader/ writer. To Re-image the CF0 Card: 1. Open WinImage. 2. From Winimage, click Disk. 3. From the menu that appears, click Restore Virtual Hard Disk image on physical drive… 4. From the Restore Virtual Hard Disk image on physical drive… window, click CF disk from the physical drive list offered, and then click OK. 5. In the Windows browser window navigate to the folder where the GApplication 7zip contents were extracted and locate the GApplication.vhd file. 6. Right-click the GApplication.vhd file, and then click Open. A warning message appears confirming which physical drive you are about to restore the image. 7. Ensure that the CF card drive is selected and not the PC’s hard disk. 8. Click Yes. The image restoration begins. and the progress window appears. 9. If a disk writing error appears: a. Click OK to close the error message. b. Close all windows that are open on the PC, including the WinImage application. c. Open the Windows browser window. d. Locate the CF card drive e. Right-click the card and click Eject. 6/18/2024 101 Version: 5.19::4 Chapter 3 - System Installation and Configuration f. Remove the CF card from the reader/writer and then re-insert it. g. Return to Step 1 and repeat the procedure. 10. When the restoration completes successfully: a. Locate the CF card drive. b. Right-click the card and click Eject. c. Remove the CF card from the reader/writer. To Re-install the CF0 Card into the Tabulator: 1. Reinstall the CF0 card back into the tabulator’s CF0 slot. 2. Replace the metal plate over the CF0 card slot and secure it with the screws. To Confirm the CF0 Card’s New Data Partition Size: 1. Power up the tabulator. Once tabulator boots up, various messages regarding unexpected conditions detected might be displayed. 2. Press Next to view each message. 3. Press OK at the final message. 4. When the message “Startup error” appears, disregard. 5. Log into the Technician Menu: a. Apply the ICE Technician Key. b. Enter the credentials. 6. From the Technician Menu, press Diagnostics. 7. From the Diagnostics screen. click System Status. 8. From the System Status screen, go to the CF Status section. 9. Review the value in the System card data partition field. 10. Verify that the partition size (including the free space) is over 3000 MB. The CF0’s data partition size is increased. 6/18/2024 102 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.4.5.2Loading new Languages onto the ICE If the ICE requires a new language, new language font files, provided by Dominion Voting, must be loaded onto the ICE via a blank CF card. The following is a listing of the files that will be provided for this procedure: • ConfigurationSignaturePool.xml • ConfigurationSignaturePool.xml.hmac • fonts.tar.bz2 • fonts.tar.bz2.hmac • fonts.tar.bz2.sha This procedure requires the following: • PC with a CF card reader/writer • Blank CF card To load the new language font files onto the ICE: 1. Ensure the ICE is powered off. 2. Copy the provided language font files onto a PC. 3. At the PC, insert the blank CF card into the card reader/writer. 4. Copy the language font files to the CF card and remove the card from the reader/writer. 5. At the ICE, insert the CF card into the CF1 slot. 6. Turn on the ICE. NOTE: If an error dialog prompt appears, press OK until the insert Admin key screen displays. 7. Apply the ICE Technician Key. 8. Enter the Technician credentials. 9. From the Technician menu, press System Update > Configuration Update. 10. Press the Update button for Font Files.The language font files are loaded onto the ICE.A message appears stating the update is completed. 11. From the top right-corner of the screen, press the power icon. If prompted, turn off the unit by pressing the Shut Down button. 12. Lift the monitor to turn the unit on. 6/18/2024 103 Version: 5.19::4 Chapter 3 - System Installation and Configuration 3.4.6 ImageCast® Precinct 2 Configuration ® The ImageCast Precinct 2 Ballot Counter device is a precinct optical scan ballot counter (also commonly referred to as a tabulator in the election industry) (see Figure 2.3). It is designed to provide two major functionalities: • Ballot scanning and tabulation • Ballot review and second chance voting ® Figure 3-9: ImageCast Precinct 2 Ballot Counter Before any of these functions can take place, the tabulator first goes through a startup procedure that initializes all hardware and all software modules, authenticating the firmware and all external election files. 1. The startup process of the tabulator consists of the following steps: a. The processor loads the boot loader from the onboard flash memory. b. The boot loader loads the uClinux operating system from the onboard flash memory. c. The operating system initializes the hardware and subsystems. (SDRAM, serial devices, buses, interrupts lines, driver modules, file system, system time, etc.) d. The operating system verifies and starts the election application from the onboard flash memory. 2. The startup procedure of the election application consists of the following steps: a. Initialize all hardware devices and run diagnostics. 6/18/2024 104 Version: 5.19::4 Chapter 3 - System Installation and Configuration b. Initialize all software modules. 3. Once the system startup phase is completed, the main processor cycles through an event loop while it waits for key events to take place. These events include: a. Paper sensor triggered to inform the application that a ballot has been inserted. b. An Administrative iButton Security Key inserted to inform the application that the administrator needs to activate certain administrative actions (print log report, enable test ballot state, close the poll, shutdown the system, etc.). c. Check the battery signal interrupt. d. Check for critical events (compact flash ejected, memory failure, etc.) 3.4.7 ImageCast® X Configuration ® ImageCast X can be used as a ballot marking device (BMD) for either, election ® day, or early voting. The resulting ballots can be scanned on the ImageCast ® ® Evolution, ImageCast Precinct 2 tabulator or the ImageCast Central tabulator. ® The ImageCast X-BMD configuration can also be utilized for curb-side voting, by installing all necessary components onto a cart. 3.5 Acceptance Testing Acceptance testing confirms that the equipment and/or software received is in good working order. For this purpose, there is no specific election project, settings or configurations. Usually, jurisdictions will choose to use the default test project, such as Famous Names project to run the acceptance test. • Election Management System Acceptance Testing ® • ImageCast Evolution Acceptance Testing ® • ImageCast Central Acceptance Testing ® • ImageCast Precinct 2 Acceptance Testing ® • ImageCast X Acceptance Testing 3.5.1 Election Management System Acceptance Testing To perform acceptance testing on the Election Management System, the supervisory election official or designee must complete the following steps: 1. Restore Election Project (refer to 12.2.2"Restoring an Election Project”). 6/18/2024 105 Version: 5.19::4 Chapter 3 - System Installation and Configuration NOTE: If you are opening an EMS application (EED, RTR, EDT, etc.) for the first time, you must set the network parameters. Enter all data required. • EMS Application Server Host (IP Address or Name): Enter in the name of the EMS application server host. • TCP Communication Port: 80. • EMS Application Server Name: emsapplicationserver. • Once all data is entered, click the Test button. If the settings are correct, you will receive confirmation in the grey dialog box. If you do not receive a confirmation, correct your settings or contact your IT personnel for the proper credentials. Click the OK button to continue. 2. Open EED and then open the restored project by navigating to Election Project > Open Project. 3. In the 'Open Project' window, select your project from the list of available election projects and click OK. 4. A login dialog appears. Enter the credentials you created when creating the Election Project. NOTE: The username and password fields are case sensitive. 5. Upon successful login, if a dialog appears indicating that the ballot style has not been set, click OK, and inspect the project to verify that the data is present. 6. In order to log in to EMS RTR and verify that you can open and inspect the project, first, you will need to assign a user to the RTR Administrative role. Select the Administration > Application Users option. 7. In the middle window pane, from the Application drop-down list, select EMS RTR and then click Create New. 8. On the Application User dialog, enter the following information: a. Enter a username. b. From the Role drop-down menu, select the role that the new user will be assigned. c. Choose whether or not you wish to create a password manually or click the Generate Password button. If you choose manually, enter a case sensitive password in the enabled fields. d. Add the relevant contact information on the right-side of the dialog. NOTE: Password Security Requirements: • Default password type: Minimum length is 8 characters which must include at least one number and one letter from the alphabet. 6/18/2024 106 Version: 5.19::4 Chapter 3 - System Installation and Configuration • Strong password type: Minimum length should be 10 characters which must include at least one number, one special character and one letter from the alphabet. • Weak password type: minimum six characters. e. Click Save and Close. 9. After saving the new user account: a. Select the user from the list by double-clicking it. b. Select the status drop-down. c. Change the status from "Initial" to "Active". d. Click Save and Close. 10. Open RTR application. 11. Click Election Project > Open Project. NOTE: If you are opening the application for the first time you must set the network parameters. Enter all data required. 12. Once all data is entered, click Test. If the settings are correct, you will receive a confirmation message. If you do not receive a confirmation, correct your settings, or contact your IT personnel for the proper credentials. Click OK. 'The Open Project' screen appears. Click on the desired project to select it, and click OK. NOTE: Only projects in “Ready for Elections” state can be accessed in RTR. If the desired project is not seen in the “Open Project” window, then election files have not been generated for that project yet. 13. In the election project Login window, enter the credentials for the Results Tally & Reporting administrator and click OK. After successfully logging into RTR, the application expands to include new menu items and the status bar is updated to contain project and user detail. Once the acceptance testing of EMS has been completed, proceed to the next section of this document. 3.5.2 ImageCast® Evolution Acceptance Testing ® Acceptance testing for the ImageCast Evolution (ICE) tabulator unit is simply a matter of confirming that the physical and electro-mechanical components are functioning properly and have not been damaged during transport, and that 6/18/2024 107 Version: 5.19::4 Chapter 3 - System Installation and Configuration certain internal parameters have been programmed correctly. Performing this testing will ensure the integrity of the installed firmware within the voting machines. It should be performed prior to each election. To perform acceptance testing, the supervisory election official or designee must complete the following steps: 1. Unpack the ICE unit and place it on an assembled ballot box. 2. Insert the test CompactFlash cards provided with the ICE unit. 3. Connect the ATI to the ICE using the RJ-45 cable provided. 4. Plug the power supply into a suitable 120 volt AC power source, and connect the power supply to the ICE. 5. Lift the LCD monitor into the upright position. 6. Turn on the main power switch under the thermal printer door. The ICE unit will begin the power-up sequence, and the LCD will display a number of messages at each stage of the sequence. 7. Once the ICE has powered up, when prompted, press the iButton security key firmly to the iButton receptacle, and hold it in place until the login screen appears on the touchscreen. 8. On the authorization screen, enter the username and password specific for to project and press the OK button. In the event that the username and password are incorrect, the screen will clear the text and provide a new opportunity to enter the correct username and password. 9. On the LCD screen check whether the battery icon indicates that the AC power supply is present. 10. Ensure the internal battery is fully charged. There are two ways to do so: a. The LCD display is used to display the internal battery status in the same manner as cell phones. There are six different indications that can be shown on the screen: • No battery (system on AC/DC power) • Almost empty • 25% full • 50% full • 75% full • 100% full b. Check the externally visible LEDs on the right side of the unit to ensure that the AC power is connected and to determine the status of the internal battery. 6/18/2024 108 Version: 5.19::4 Chapter 3 - System Installation and Configuration ® c. When the ImageCast Evolution is powered down, using the tip of a pen or paper-clip, press the recessed battery level button to the right of the LEDs. The LEDs will light up to show the battery's current charge. 11. Ensure the security icon (in shape of a padlock) is white. When security has been compromised, the icon will turn red. 12. Ensure the system health icon is white. When the system health has been compromised, the icon will turn red. For example, if the ATI is missing, the icon will turn red. 13. In addition to the steps described above, the ICE unit has multiple procedures available for polling place verification: a. The election's identification data is available via printed report and on- screen. a. Identification of the unit is only available on-screen. b. Identification of all ballot formats is available on a printed report. c. The vote totals for each active candidate and measure on all storage locations (showing that they contain only zeros, i.e. zero tape) are available on a printed report. d. A list of all ballot fields that can be used to invoke special voting options are available on a printed report. More extensive diagnostic tests and procedures are contained within the Technician menu and can be conducted by authorized vendor technical staff. 3.5.3 ImageCast® Central Acceptance Testing ® Acceptance testing for the ImageCast Central (ICC) scanner is simply a matter of confirming that the physical and electro- mechanical components are functioning properly and have not been damaged during transport, and that certain internal parameters have been programmed correctly. Performing this test will ensure the integrity of the installed firmware within the voting machines. It should be performed prior to each election and initially for customer acceptance testing. To perform acceptance testing, the supervisory election official or designee must complete the following steps: 1. Unpack the ICC scanner and place it on the desired workstation surface next to the PC workstation. 2. Attach the USB cable from the scanner to the PC workstation. 3. Plug the scanner and the PC workstation into a suitable 120V AC power source. 4. Power up the scanner and PC workstation. 6/18/2024 109 Version: 5.19::4 Chapter 3 - System Installation and Configuration 5. Copy the ICC election files from the EMS to each ICC workstation being tested. 6. Log onto the computer. ® 7. On the PC, run the ImageCast Central application. 8. Insert the iButton security key and enter the passcode. The application will verify the iButton Security Key against the election files. Errors at this point indicate that the iButton security key has not be programmed correctly, and a replacement key may need to be ordered. Otherwise, the application will commence internal diagnostics testing before going into user's mode. 3.5.4 ImageCast® Precinct 2 Acceptance Testing ® Acceptance testing for the ImageCast Precinct 2 tabulator unit is a matter of confirming that the physical and electromechanical components are functioning properly and have not been damaged during transport, and that certain internal parameters have been programmed correctly. Performing this testing will ensure the integrity of the installed firmware within the voting machines. It should be performed prior to each election. To perform acceptance testing, the supervisory election official or designee must complete the following steps: ® 1. Unpack the ImageCast Precinct 2 tabulator unit and place it on an assembled ballot box. ® 2. Insert the test SD cards provided with the ImageCast Precinct 2 tabulator unit. 3. Plug the power supply into a suitable 120 volt AC power source, and connect ® the power supply to the ImageCast Precinct 2 device. ® 4. The ImageCast Precinct 2 will begin the power-up sequence, and the LCD will display a number of messages at each stage of the sequence. ® 5. Once the start-up sequence is complete, the ImageCast Precinct 2 will alert the attendant using a series of audible beeps, and a message on the LCD screen will prompt him/her to insert the security key into the iButton Security Key and enter their password. ® 6. As soon as the election files are authenticated, the ImageCast Precinct 2 will start up in Administration Mode, and will show the Main menu on the LCD screen. 3.5.5 ImageCast® X Acceptance Testing ® Acceptance testing for the ImageCast X tabulator unit (ICX) is simply a matter of confirming that the physical and electro-mechanical components are functioning properly and have not been damaged during transport and that 6/18/2024 110 Version: 5.19::4 Chapter 3 - System Installation and Configuration certain internal parameters have been programmed correctly. Performing this testing will ensure the integrity of the installed firmware within the voting machines. It should be performed prior to each election. To perform acceptance testing, the supervisory election official or designee must complete the following steps: 1. Unpack the ICX and place it on a table. 2. Unpack the printer and place it next to the ICX. 3. Insert the USB drive with test election data provided with the ICX. 4. Connect the ATI to the ICX using the USB to RJ-45 adapter provided. 5. Connect the power supply into a suitable 120 volt AC power source, and connect the power supply to the ICX. 6. Open the bottom security door on the rear of the device and press and hold the power button until it lights up green. The ICX will begin the power-up sequence, and the LCD will display a number of messages at each stage of the sequence. 7. Insert the technician Smart Card (refer to D.2.7.3"Programming Technician Smart Cards”) into the smart card reader. Wait for the login screen to appear. 8. On the Authorization screen, enter a valid PIN. NOTE: In the event that the PIN is incorrect, the screen will clear the text and provide a new opportunity to enter the correct PIN. After 8 attempts, the smart card will lock and you will have to obtain a new smart card. The user is presented with Technical Administration screen. 9. Once logged in, confirm or modify the date and time. 10. Connect the USB drive containing the election data (refer to D.2.7.3 "Programming Technician Smart Cards”). 11. Select the Load Settings button on the Technical Administration page. 12. Copy the election files (.dat) onto the device. Wait until the election files are copied. 13. Eject the USB drive. 14. Navigate to Android Settings > Select Battery. 15. Ensure that the battery is 100% full and that it is connected to AC power. 16. Remove the technician Smart Card. 17. Insert the poll worker Smart Card (refer to D.2.7.3 "Programming Technician Smart Cards”) into the smart card reader. Wait for the login screen appears on the touchscreen. 18. On the Authorization screen, enter a valid PIN in order to log in. 6/18/2024 111 Version: 5.19::4 Chapter 3 - System Installation and Configuration NOTE: In the event that the PIN is incorrect, the screen will clear the text and provide a new opportunity to enter the correct PIN. After 8 attempts, the smart card will lock and you will have to obtain a new smart card. 19. Wait for the election files to decrypt. 20. Ensure the required tabulator is present in the tabulator list. 21. In addition to the steps described above, the ICX unit has multiple procedures available for polling place verification: a. The election's identification data is available on-screen. • The information is available as part of the Ballot Information screen shown to every voter after successful ballot activation. b. Identification of the unit is available on-screen only. • Log in as technician (see steps 10 and 11 from the Settings section), select the Hardware Details button. ICX device details are shown as part of the "ICX Device" section. • To exit the menu, click OK. • Remove the technician Smart Card. NOTE: More extensive diagnostic tests and procedures are found in the technician menu and can be conducted by authorized vendor technical staff. 6/18/2024 112 Version: 5.19::4 Chapter 4 - Election Set-up and Definition CHAPTER 4: ELECTION SET-UP AND DEFINITION This chapter describes the procedures used to verify proper functioning of the ® equipment and entire Democracy Suite system. Included in this chapter is information about the following: • Election Project Database Programming and Configuration • Tabulator Programming and Configuration • System Diagnostics Testing Procedures • System Proofing • Logic and Accuracy Testing of System and Components • Election Observer Panel • Hardware Maintenance and Preparation for Use • Physical Security of Equipment ® Overview: After installation, the Democracy Suite system can be tested to verify that the products are configured to run as an integrated system. The tests involved ® ® may be performed using the single ImageCast Evolution, ImageCast Precinct ® ® 2, ImageCast X and/or ImageCast Central tabulator. Prior to running any system level tests, a series of diagnostic tests may be run to ® identify any existing or potential issues with the ImageCast Evolution and ® ® ImageCast Central, and ImageCast Precinct 2 tabulators. Once the diagnostic tests are completed, the readiness testing will be executed to determine that the system has been configured properly and that the equipment functions correctly. Finally, logic and accuracy testing is run prior to the election to ensure that the election project has been programmed and configured correctly. Every device is to be retested prior to every election. The election project database may be provided by Dominion Voting. If the election project database is provided by Dominion Voting, then the administrator must first restore the election project (see section 12.2.2 “Restoring an Election Project”). Once the project is restored, return here and proceed to section 4.2“Tabulator Programming and Configuration”. If the jurisdiction is defining their election project database themselves, begin with the next section (see section 4.1 “Election Project Database Programming and Configuration”. 6/18/2024 113 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 4.1 Election Project Database Programming and Configuration Defining and configuring an election is accomplished through the Election Event Designer (EED) application and consists of the following steps. 1. Create a new project 2. Define District types 3. Define districts 4. Define precincts 5. Define district rotations 6. Rotate contests 7. Define ballots structure 8. Preview ballots 9. Run proofing reports 10. Generate proofing ballots 11. Generate official ballots 12. Define tabulators and configurations 13. Generate Election files ® For detailed information and how to use EED, please see the Democracy Suite EMS Election Event Designer User Guide. Jurisdictions that program their own elections will create their projects according to the custom use procedure document created for them by Dominion Voting Systems, which they will receive after purchasing the System. Additionally, specific procedures and tips for creating election projects in EED are contained in the section D.2.1“Creating Election Project”. 4.2 Tabulator Programming and Configuration System readiness testing consists of an end to end system test that helps to ensure that the system has been configured properly and that all parts of it function correctly. The test consists of pre-voting, voting and post-voting phases. • Pre-voting phase testing consists of restoring and, if necessary, modifying the election project to be used for readiness testing as well as preparing all other necessary material for testing such as iButtons, security keys, test decks etc. • The voting phase consists of scanning the test decks on all physical tabulators. 6/18/2024 114 Version: 5.19::4 Chapter 4 - Election Set-up and Definition • The post-voting phase involves loading results and analyzing the reports. In relation to these test phases, this section contains information about the following: • Performing the Pre-Voting Phase Readiness Test • Performing the Voting Phase Readiness Test ® • Voting Phase Readiness Testing ImageCast X • Performing the Election Day Phase Readiness Test 4.2.1 Performing the Pre-Voting Phase Readiness Test Tabulator pre-voting readiness tests can be performed with any suitable ® Democracy Suite election project and ballots. Dominion Voting Systems may provide state-specific demonstration and/or acceptance test election projects for this purpose, or the jurisdiction can develop their own. Jurisdictions that have their elections programmed by Dominion Voting should proceed to section 12.2.2“Restoring an Election Project” to restore the test election database and then return here to continue. Jurisdictions that program their own elections will create their projects according to the custom use procedure document created for them by Dominion Voting Systems, which they will receive after purchasing the system. In addition, specific procedures and tips for creating election projects in EED are contained in the section D.2.1“Creating Election Project”. 6/18/2024 115 Version: 5.19::4 Chapter 4 - Election Set-up and Definition Prepare the external media and other artifacts: • Program the iButton security keys in EED See section D.2.7.2“Programming of iButton Security Key”. • Program the ImageCast® Evolution CF cards in EED See section D.2.7.1“Programming of CF/SD Cards”. • Program the ImageCast® Precinct 2 SD cards See section D.2.7.1“Programming of CF/SD Cards”. • Program the ImageCast® X USB drives See section D.2.7.4“Program USB flash drive for ImageCast X Devices” • Copy election files for ICC tabulators onto USB drives from the EMS server and load the election files onto each ICC Workstation ® See section 7.4“Loading an Election to the ImageCast Central System”. • Program the poll worker smart cards See section D.2.8“Programming of poll worker Smart Card”. • Prepare the test decks with known results See section 4.5.1.3“Test Decks Required for Logic and Accuracy Testing”. NOTE: Depending on the expiration date set on the Adjudication certificate, your Administrator might need to create a new certificate and install it on the EMS Server as well as the remote adjudication client workstations (see section 3.3.3.13 “Installing Trusted Server Certificate”). Once this step is complete, the voting phase readiness test can begin. 6/18/2024 116 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 4.2.2 Performing the Voting Phase Readiness Test ® Voting phase readiness test is performed on all ImageCast tabulators. It involves scanning a pre-marked test deck of ballots (with a known set of results) for the specific election. This section contains information about the following: ® • Voting Phase Readiness Testing ImageCast Evolution ® • Voting Phase Readiness Testing ImageCast Central ® • Voting Phase Readiness for ImageCast Precinct 2 ® 4.2.2.1 Voting Phase Readiness Testing ImageCast Evolution ® This section describes the readiness testing procedure for the ImageCast Evolution tabulators. The procedure consists of loading CF cards containing ® election files on each ImageCast Evolution tabulator and testing it by scanning test decks and verifying the results reports. ® NOTE: Make sure to test every physical ImageCast Evolution tabulator that might be used for early voting or election day. 1. On the ICE tabulator, insert the memory card containing the election project into the CF1 card slot, and the initialized backup memory card into the CF2 card slot. 2. Power up the ICE tabulator by lifting the LCD monitor into the operating position (note that the main power switch under the thermal printer door needs to be switched on). 3. When prompted by the LCD screen, apply the iButton Security Key and enter the appropriate password. 4. Visually confirm that the date and time are correct by looking at the lower left section of the ICE LCD screen (if date and/or time need to be changed, please consult with designated ICE level 1 technician). 5. Open the polls by pressing the Open Poll button on the Poll Management screen. 6. Tabulate the pre-marked test deck of readiness testing ballots using the ICE tabulator by feeding the test deck, and then continue with next steps below. 7. Start an accessible voting session and vote a predefined voting pattern. 8. After all ballots have been tabulated and accessible voting sessions have been completed, apply the iButton Security Key and close the polls. 9. Allow at least one result tape to print and confirm that you do not need another copy. 6/18/2024 117 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 10. Power down the unit by tapping the Shut Down icon at the top right corner of the screen. 11. On the right side of the ICE open the CF1 and CF2 card slot doors and remove both cards from the tabulator. Set the cards aside, noting which tabulator they were retrieved from. These cards will be used for tally in the Results Tally & Reporting application. 12. For each tabulator tested, confirm that the tabulator-level result reports match the expected results from the pre-marked test deck. 13. Repeat this test procedure for each physical ICE tabulator. ® 4.2.2.2 Voting Phase Readiness Testing ImageCast Central ® This section describes the readiness testing procedure for the ImageCast Central 2 tabulators. The procedure consists of loading of ICC election files onto the ICC workstation and testing each of the ICC tabulators by scanning test decks and verifying the results reports. Before you begin: Archive any previous results by exporting them from the application. Before ® continuing, ensure that the ImageCast Central workstation and scanner are powered on and ready to load election files. If the ICC workstation is already set up, continue with the next step. 1. Open the ICC application by double-clicking the ICC icon. Attach the appropriate iButton to the iButton reader. 2. Load the desired tabulator. To switch tabulators, select All Tabulators from the Configure menu on the ICC application and load the appropriate tabulator. 3. Generate the Zero Report by selecting the Review option, selecting all listed batches, and then clicking the Generate report button. 4. From the Configure screen, set the Secondary Path by clicking the Set New Path button and browsing to the appropriate location on the NAS. 5. Enter Scanning Mode by selecting the Scan button from the left pane of the application. 6. Tabulate the test deck by clicking on the Scan button. Accept each batch of test decks by clicking Accept button. 7. Close the tabulator by clicking on the Configure menu, and then selecting the Close button. 8. Generate Results Report(s) (see section 7.9.4“Producing Reports from the ® ImageCast Central System and Closing the Tabulator”). 9. Repeat steps 1 through to 7 for each ICC physical tabulator. 6/18/2024 118 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 10. For each tabulator tested, confirm that the tabulator-level result reports match the expected results from the pre-marked test deck. 11. Exit the ICC application by clicking the QUIT button. A confirmation dialog will appear. 12. Click OK to close the dialog and exit the application. 13. When all tabulators have been tested, proceed to the next section. 6/18/2024 119 Version: 5.19::4 Chapter 4 - Election Set-up and Definition ® 4.2.2.3 Voting Phase Readiness for ImageCast Precinct 2 ® This section describes the readiness testing procedure for the ImageCast Precinct 2 tabulators. The procedure consists of loading SD cards containing election files on each ICP2 tabulator and testing it by scanning test decks and verifying the results reports. NOTE: Make sure to test every physical ICP2 tabulator that might be used for early voting or election day. 1. On the ICP2 tabulator, insert the memory card containing the election project into the SD1 card slot, and the initialized backup memory card into the SD2 card slot. 2. Power up the ICP2 tabulator: using a pen or stylus, press in the Power button to the left of three LED lights next to the Administrator port door and hold for 2-3 seconds. A solid green light will display on the front left of the scanner. 3. When prompted by the LCD screen, apply the iButton Security Key and enter the appropriate password. 4. Open the polls by selecting the Open Polls button from the Poll Management screen. 5. Tabulate the pre-marked test deck of readiness testing ballots into the ICP2 tabulator by feeding the test deck through the tabulator, one ballot at a time. 6. After all ballots have been tabulated, apply the iButton Security Key to the receptacle and enter the PIN. From the Main Menu screen that displays, select Poll Management then select Close Poll. Enter the PIN, select the Print button to print a results report and then press Next. Enter the number of copies of the report to print (at least 1) and tap Next. If prompted to print the Write-in Report select Don’t Print. From the Close Poll Confirmation screen, press Confirm. 7. Allow at least one result tape to print and confirm that you do not need another copy. 8. Power down the ICP2 by selecting Utilities from the Main Menu then select Power Down... Press Confirm. 9. Open the SD1 and SD2 card slot doors and remove both cards from the tabulator. Place both cards in the envelope provided. These cards will be used for tally in the Results Tally & Reporting (RTR) application. 10. For each tabulator tested, confirm that the tabulator-level result reports match the expected results from the pre-marked test deck. 11. Repeat this test procedure for each physical ICP2 tabulator. 6/18/2024 120 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 4.2.3 Voting Phase Readiness Testing ImageCast® X NOTE: The procedure consists of inserting USB removable mediums containing election files and VoteSims into each ImageCast® X ballot marking device, scanning the marked ballots (test deck), and verifying the results reports. ® Make sure to test every physical ImageCast X ballot marking device that might be used for early voting or election day. 1. On the ICX ballot marking device, insert the USB media containing the election project into the top USB slot. 2. Power up the ICX ballot marking device by pressing the power button on the back side. 3. Insert the technician smart card, and enter the appropriate PIN. 4. Confirm or modify the date and time. 5. Press the Clear Working Directory icon. From the Warning dialog, press Yes to confirm. Enter Technician PIN and press Confirm. Click OK on the Info dialog. 6. Press the Clear All Election Data icon. From the Warning dialog, press Yes to confirm. Enter the Technician PIN and press Confirm. Click OK on the Info dialog. 7. Load the election files by completing the following: • Press Load Election Data. • Select the .dat file for the ICX. • On the Confirm dialog, press Confirm. The Status dialog displays during copy. • On the Confirm dialog, press Copy. 8. Remove the Technician smart card. 9. Insert the Poll Worker smart card and enter the PIN. 10. Wait for the election files to decrypt. 11. Select the appropriate ballot marking device from the tabulator drop down list. 12. Open the Polls by pressing the Open Poll button from the Poll Administration menu. 13. Remove the Poll Worker smart card. 14. To activate the Vote Sim: • Insert the Technician smart card. 6/18/2024 121 Version: 5.19::4 Chapter 4 - Election Set-up and Definition • Input the PIN. • Press the Load Test Pattern button. • Insert the USB containing the VoteSim files. • From the USB drive dialog select the XML for the device being tested. • Remove the Technician card and insert the Voter card. The Vote Simulation test will automatically begin. 15. Mark the ballots as indicated in the pre-marked test deck of readiness testing ballots and then return here to continue with next steps below. 16. Start an accessible voting session and vote at least one ballot using a pre- defined pattern (to ensure that the results of these ballots are accounted for in the expected results). 17. After all ballots have been marked, insert the Poll Worker Smart Card, input the PIN and close the polls. Note: the marked ballots must still be tabulated. 18. Power down the unit by pressing the Power Off icon at the bottom-right corner of the screen. 19. Repeat this test procedure for each physical ICX tabulator. 20. Feed the marked ballots into either the ICE tabulator, ICC tabulator, or ICP2 tabulator. 4.2.4 Performing the Election Day Phase Readiness Test This section provides instructions on how to tally and report results from the ® ® ® ImageCast Evolution, ImageCast Precinct 2 and ImageCast Central tabulators. Additional instructions can be found in the Help menu within the EMS Results Tally & Reporting application (RTR). 1. Open the RTR application. If the project was created by the Dominion Voting, the RTR username and password will be provided to the jurisdiction. Jurisdictions programming their own elections will have to have their administrator create an RTR user account and activate it in EED (see section 12.2.7“Creation of RTR User in Election Event Designer”). 2. Open the appropriate election project by selecting Election Project from the top menu then select Open Project. 3. Load the results files, audit log files and result images from the ICE or ICP2 and the ICC tabulators into the RTR application. Once all result files are uploaded continue with the next step. Note: For additional instructions on loading results, consult the RTR User Guide from the Help Menu in RTR. 4. Validate and publish results files in the RTR application. 6/18/2024 122 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 5. Create the Election Summary Report, ensuring to include all relevant results files created from the tabulation of test decks. 6. Confirm that the results from the election summary report from RTR matches the tabulator summary reports and the expected test deck results. 7. Review a subset of Audit Marked images in order to confirm that ballot image files are clear and readable and to verify that the system is interpreting the individual ballots accurately. 4.3 System Diagnostics Testing Procedures This section defines the system diagnostic testing procedures, which are ® performed to identify any existing or potential issues with the ImageCast series of tabulators/units. If any device fails diagnostic testing or a component of diagnostic testing, please refer to Appendix F“Troubleshooting and Problem Resolution”. This section contains the following information: ® • ImageCast Central System Diagnostics Testing Procedures ® • ImageCast Evolution System Diagnostic Testing Procedures ® • ImageCast Precinct 2 Diagnostic Procedures ® • ImageCast X Diagnostic Procedures 6/18/2024 123 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 4.3.1 ImageCast® Central System Diagnostics Testing Procedures • To perform diagnostic testing on the ICC, the election files need to be loaded on the workstation. • For instructions on how to load election files and prepare an ICC workstation for diagnostic testing, see section see section 3 “Click Apply, and then click OK to close.”. • Ensure that the iButton security key for the loaded project has been programmed (see section D.2.7.2“Programming of iButton Security Key”) and connected to the same ICC workstation. ® • Open the ImageCast Central application and the scanning device will automatically perform a set of diagnostic tests. The tests are run after every power cycle. The system generates a report at the end of the diagnostics testing procedure that outlines the status of the system. • To display this report navigate to the administrator's Status menu and press ® the Show Log button in the ImageCast Central application. 4.3.2 ImageCast® Evolution System Diagnostic Testing Procedures ® Prior to running pre-election diagnostic tests on the ImageCast Evolution, a trained service technician must first login as technician in order to access the diagnostics options in the Technician menu. The trained service technician must have an iButton technician security key, username, and password before performing the following: • Automated tests • Functional tests Automated Tests Functional Tests Memory Audio Compact Flash Video EEPROM Scanner Thermal Printer Printer Table 4-1: List of Functional Tests 6/18/2024 124 Version: 5.19::4 Chapter 4 - Election Set-up and Definition Automated Tests Functional Tests Ballot Marking Printer ATI Video Sip and Puff or Paddle ATI Virtual Keyboard Audio Voting Buttons Internal Clock System Test Power Communication Test Scanner Power On Self Tests (POST) Table 4-1: List of Functional Tests ® A diagnostics report can be printed via the ImageCast Evolution thermal printer and retained for auditing purposes. 1. Power up the ICE by pressing the main power switch located under the thermal printer door. 2. When prompted by the touchscreen, touch the technician iButton security key to the security key receptacle, and enter the technician username and password. If you are unsure of the password, contact your elections supervisor for assistance. The Technician menu will appear. 3. Under the Technician main menu, press the Diagnostics button. 4. Ensure the paper roll is installed in the thermal printer. 5. Ensure the printer inkjet cartridge is installed. 6. Ensure the ATI and headphones are connected. 6/18/2024 125 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 4.3.3 ImageCast® Precinct 2 Diagnostic Procedures ® ImageCast Precinct 2 does not require diagnostic procedures. During the tabulator’s boot-up, ICP2 verifies all system components. 4.3.4 ImageCast® X Diagnostic Procedures ® Prior to running pre-election diagnostic tests on the ImageCast X, a trained service technician must first login as technician in order to access the diagnostics options in the Technician menu. The trained service technician must have a technician smart card and a valid PIN for the card before performing the following: • Automated Tests • Automated tests (POST - Power-On Self-Test) are performed at the system start. The system will not initialize if any of the tests fail. The tests include: • Power • Memory • CPU • Video subsystem • Audio subsystem • Hardware Tests: • ATI • Paddles • Sip & puff • Printer • LED Lamp • Touchscreen 4.4 System Proofing Jurisdictional Report Proofing Proofing report list: • Districts Report – Lists each district in the election project and its associated precincts. If there are any split precincts active in the election, that information will be reflected in this report. 6/18/2024 126 Version: 5.19::4 Chapter 4 - Election Set-up and Definition • Precincts Report – Lists each precinct in the election project and its associated districts. If there are any split precincts active in the election, this report will indicate that a precinct has splits but split precinct detail will not be reflected in this report. • Tabulators Report – Lists each tabulator in the election project, the polling location the tabulator is assigned to, the tabulator type, the assigned counting group, and the precincts assigned to the tabulator. • Ballot Types Report – Lists each ballot type in the election project and its associated contests and precincts. If a contest rotates the candidate position is identified. • Contests Report – Lists each contest in the election, the associated district, the candidate(s)/choice(s), and the associated elector group. The elector group will only be a factor in a primary election where a contest is associated with a party for the purpose of creating separate partisan ballots. Districts Report This report is used to verify that the districts that are active in the election are present and associated with the proper precinct(s). Generating the Districts Report: 1. Open EED. 2. Log into the election project. 3. From the left navigation pane, expand the Reports subsection. 4. Select the Divisioning report group. 5. From the Report Name drop-down menu, select the Districts Report. 6/18/2024 127 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 6. Select Create New to create a new report. 7. Select the desired output (PDF, Excel, Word). Select or clear any desired output fields, as necessary. 8. Click Create. 6/18/2024 128 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 9. Select the method you wish to view the report (e.g. Preview in a new window, Export, or Save To NAS). The preferred method is to save the report to the NAS. 10. A progress bar will display as the report is generating. 11. The report will open in a new window. The report will also be saved to the project’s report folder on the NAS: D:\NAS\Election Name\Reports\Districts 6/18/2024 129 Version: 5.19::4 Chapter 4 - Election Set-up and Definition Once the report has generated, the report should be proofed for the following details: • Verify that every district that should be in the election project is listed. For each district: • Verify that every precinct that belongs in the district is listed. Precincts Report This report is used to verify that each precinct included in the election is present. Generating the Precincts Report: 1. Open EED. 2. Log into the election project. 3. From the left navigation pane, expand the Reports subsection. 4. Select the Divisioning report group. 6/18/2024 130 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 5. From the Report Name drop-down menu, select the Precincts report. 6. Select Create New to create a new report. 7. Select the desired output (PDF, Excel, Word). Select or clear any desired output fields, as necessary. 8. Click Create. 9. Select the method you wish to view the report (e.g. Preview in a new window, Export, or Save To NAS). The preferred method is to save the report to the NAS. 6/18/2024 131 Version: 5.19::4 Chapter 4 - Election Set-up and Definition A progress bar will display as the report is generating. 10. The report will open in a new window. The report will also be saved to the project’s report folder on the NAS: D:\NAS\Election Name\Reports\Precincts Once the report has generated, the report should be proofed for the following details: • Verify that every precinct that should be in the election project is listed For each precinct: 6/18/2024 132 Version: 5.19::4 Chapter 4 - Election Set-up and Definition • Verify that every district that is associated with the precinct in the current election is listed Tabulators Report This report is used to verify that every tabulator being used in the election is present and that each one is associated with the proper polling place, counting group, and precinct(s). Generating the Tabulators Report: 1. Open EED. 2. Log into the election project. 3. From the left navigation pane, expand the Reports subsection. 4. Select the Tabulation report group. 5. From the Report Name drop-down menu, select the Tabulators report. 6. Select Create New to create a new report. 7. Select the desired output (PDF, Excel, Word). Select or clear any desired output fields, as necessary. 8. Click Create. 6/18/2024 133 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 9. Select the method you wish to view the report (e.g. Preview in a new window, Export, or Save To NAS). The preferred method is to save the report to the NAS. 10. A progress bar will display as the report is generating. 11. The report will open in a new window. The report will also be saved to the project’s report folder on the NAS: D:\NAS\Election Name\Reports\Tabulators 6/18/2024 134 Version: 5.19::4 Chapter 4 - Election Set-up and Definition Once the report has generated, the report should be proofed for the following details: • Verify that every tabulator that should be in the election project is listed. For each tabulator: • Verify the Tabulator Name • Verify the Polling Place name • Verify the Tabulator Type • Verify the Counting Group • Verify the List of Associated Precincts This verification procedure determines which ballots the tabulator will accept. NOTE: Central count scanners should be associated with all precincts. Ballot Types Report This report is used to ensure that the correct contests and precincts are associated with each ballot type. 6/18/2024 135 Version: 5.19::4 Chapter 4 - Election Set-up and Definition NOTE: In a Presidential primary election, you will have party specific ballot types associated with each precinct. Generating the Ballot Types Report: 1. Open EED. 2. Log into the election project. 3. From the left navigation pane, expand the Reports subsection. 4. Select the Election Event report group. 5. Select the Ballot Types report. 6. Click Create New. 7. Select the desired output (PDF, Excel, Word). Select or clear any desired output fields, as necessary. 8. Click Create. 6/18/2024 136 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 9. Select the method you wish to view the report (e.g. Preview in a new window, Export, or Save To NAS). The preferred method is to save the report to the NAS. 10. The report will open in a new window. The report will also be saved to the project’s report folder on the NAS: D:\NAS\Election Name\Reports\Ballot Types. 6/18/2024 137 Version: 5.19::4 Chapter 4 - Election Set-up and Definition Once the report has generated, verify that each ballot type in the election project is listed and that the correct contests and precincts are associated with it. Contests Report This report is used to verify that each contest and its associated candidates are present. Generating the Contests Report: 1. Open EED. 2. Log into the election project. 3. From the left navigation pane, expand the Reports subsection. 4. Select the Election Event report group. 5. Select the Contests report. 6/18/2024 138 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 6. Click Create New. 7. Select the desired output (PDF, Excel, Word). Select or clear any desired output fields, as necessary. 8. Click Create. 9. Select the method you wish to view the report with (e.g. Preview in a new window, Export, or Save To NAS). The preferred method is to save the report to the NAS. 10. The report will open in a new window. The report will also be saved to the project’s report folder on the NAS: D:\NAS\Election Name\Reports\Contests. 6/18/2024 139 Version: 5.19::4 Chapter 4 - Election Set-up and Definition Once the report has generated, the following details should be proofed: • Verify that every contest in the election is present. • Verify that every contest appears only once. For each contest: • Verify the contest name is correct. NOTE: This is the name of the Contest as it will appear on ALL reports (including the Election Summary Report). The name of the contest as it appears on the ballot may be different. • Verify that the “Number of Positions” is equal to the correct number available for voting. • Verify that the district name is correct. 6/18/2024 140 Version: 5.19::4 Chapter 4 - Election Set-up and Definition • Verify the choices for each contest are listed. Visual Ballot Proofing Ballot Type Confirmation Looking at the ballots, confirm the following pieces of information about the ballot type information: • Verify that every expected ballot type is present. Ballot Header/Footer Confirm the following pieces of information about the Ballot Header and Footer information: • Verify that the official ballot header is present at the top of the ballot, and the text order is consistent and contains the following in all languages: • The title of election • The date and of the election • The county name • In Presidential primary elections, verify that the party is correct • Voting instructions • Ballot ID and precinct presented in the proper format Contest Information All of the contest information is imported into EED to create the ballot(s). • Confirm the following regarding the Contest header information: • Verify the correct contests appear on the ballot, in the correct sequence. • Verify each contest appears only once on the ballot. • Verify that the contest heading and spelling are correct and consistent. • Verify that the correct "Vote For" appears for each contest. • In Presidential primary elections, verify that only the appropriate contests are listed on the appropriate party's ballot. • Confirm the following regarding Candidates: • Verify that the correct candidates appear in each contest. • Verify that each candidate appears only once on the ballot. • Verify that the candidate names and designations are spelled correctly including punctuation. • Verify that the candidates are listed in the correct order that they should appear on the ballot. 6/18/2024 141 Version: 5.19::4 Chapter 4 - Election Set-up and Definition • Verify that the candidate names appear to be of a uniform font size for a given contest. • If there are write-in candidates, verify number of write-in(s) spaces in the appropriate contest(s) match the “Vote For” number. • Confirm the following regarding Proposals: • Verify that all title and text is correct for every proposal. Audio Ballot Proofing Your Election Proofing Package will include the Audio Studio Library Package for the purpose of proofing the audio used during audio voting sessions on the ICX, ICP, and ICE. Using this method will simplify the audio ballot proofing process 6/18/2024 142 Version: 5.19::4 Chapter 4 - Election Set-up and Definition because you will only have to proof each audio file once. For example, even though “President” may be on every ballot in your election, you will only need to listen to the audio for that contest once since the same audio file is used for every ballot. To proof the audio, you will simply need to have the Audio Studio application installed on a computer that is capable of playing audio files. When proofing the audio ballot, you are making sure that audio exists for every part of the ballot and that ballot items are stated correctly. You should proof all languages. You should also make sure to note any glaring mispronunciations of candidate names and/or garbled audio segments and correct them using the tools in Audio Studio. Listening to the Audio 1. Open the desired audio library. 2. Using the “Audio file type:” drop-down pick list located in the top-left corner of the screen, select the desired audio file type. 6/18/2024 143 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 3. Highlight one of the audio files listed by clicking on it (the corresponding text for the audio file selected will display in the center of the screen under the label “Text:”). 4. Click the Play button to hear the existing audio. 5. Repeat steps 3 and 4 to listen to each audio file listed for the currently selected audio file type. 6. Repeat steps 2 through 5 for each audio file type listed in the “Audio file type:” drop-down pick list. NOTE: Make sure that you listen to each audio file, in each audio file type, for all languages used in the election. Screen Ballot Content Proofing 1. To restore a project: a. In EED, in the top toolbar menu, click Administration. b. Select Restore EMS Database. c. Click Browse and navigate to the external media where the project resides. d. Select the project package .zip folder, and click Open. e. Click Restore. This process will take a few minutes—please be patient. 2. To open the project: a. Click Election Project in the top toolbar menu, and then select Open Project. b. Select the project you want to open, and then click OK. c. Enter your username and password, and then click OK. 6/18/2024 144 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 3. Program Technician and Poll Worker Smart Cards in EED. To program Technician Smart Cards: a. Log into a project in EED. b. Expand the Settings menu, then select Project Parameters. c. Select the Smart Card tab. d. Click the Program Smart Card button. e. A confirmation will display when the card has burned successfully. Click OK. To program Poll Worker Smart Cards: a. Log into the project in EED. b. Expand the Tabulation section on the left navigation pane. c. Select Tabulators. d. Click Search to view the list of tabulators in the project. e. Double-click on an ICX from the list. f. Click on the Users tab. g. Select the Admin user. h. Click Program Smart Card. i. A prompt will display. Insert the smart card and click OK. j. A progress bar will appear as the card is being burned. k. When the card has burned successfully, a confirmation message will appear. Click OK. 4. Program a USB media with election files: a. Log into the project in EED. b. Expand the Tabulation section on the left navigation pane. c. Select Programming Groups. d. Select the default programming group by double-clicking on it. e. Select Program USB. f. Insert a blank USB media device. 5. Load Election Files onto an ICX: a. Insert the USB media that contains the election files into the USB port located behind the top access panel. b. Insert a Technician smart card into the ICX and input the Technician PIN. 6/18/2024 145 Version: 5.19::4 Chapter 4 - Election Set-up and Definition c. Tap Load Settings and select the PG_ICX.dat file (do not select the WPSSettings.dat file). d. The files will begin to load automatically. After the election files have loaded, tap OK and remove the Technician smart card. 6. Preview ballot types manually: a. After the election files have been loaded, insert the poll worker smart card into the card reader and input the poll worker PIN. b. Confirm the date/time, if prompted. c. Select the appropriate tabulator from the list. The verification process will start automatically. d. When the verification process is complete, two checkboxes will display. If any error displays, notify a technician. e. In the settings section, select Manual Activation. f. Type in an activation code for each unique ballot type in the election. 4.5 Logic and Accuracy Testing of System and Components Formal logic and accuracy testing is required to be conducted in accordance with the elections code to ensure that the system has been configured correctly for an election. This testing is performed using the election project that is to be used in the real election and a set of ballots for which the correct results are known ahead of time. Such a test set, also called a test deck, is run through the system to ensure that the results shown by the tabulator are aligned with those expected. After logic & accuracy testing has been completed, the system must be reset in order to remove the test results. The system can then be locked away in a secure location until actual election ballots are ready to be scanned. Notify the election supervisor immediately if there are any problems or irregularities during logic & accuracy testing. If at any time during the testing the system fails or produces incorrect results that cannot be attributed to human error, notify the election supervisor immediately. This section includes information about the following: • Pre-Conditions for Performance of Tests • Logic and Accuracy Test Procedures • Logic and Accuracy System Test Acceptance Criteria and Completeness • Backing up the Logic and Accuracy Test Results • Clearing Logic and Accuracy Test Results 6/18/2024 146 Version: 5.19::4 Chapter 4 - Election Set-up and Definition • Re-zeroing the ICC • Re-zeroing the ICE • Re-zeroing the ICP2 • Re-zeroing the ICX 4.5.1 Pre-Conditions for Performance of Tests Get the media and other artifacts ready (if not provided by Dominion Voting), same as was done in the readiness testing. See 4.2.1“Performing the Pre-Voting Phase Readiness Test” for more details. This section contains information about the following: • Restore Election Project • Opening an Election Project • Pre-Testing of the Scanning setting with Official election ballots from the certified ballot printer • Test Decks Required for Logic and Accuracy Testing • Scanning the USB Media using Windows Defender • Backup of Election Project 4.5.1.1 Opening an Election Project 1. In the EED navigation, click Election Project. 2. Click Open Project. The Open Project dialog appears. 3. On the Open Project dialog, select your election project and click OK. The Login dialog appears. 4. On the Login dialog, enter the username and password. The login dialog will close and the project will open. 4.5.1.2 Pre-Testing of the Scanning setting with Official election ballots from the certified ballot printer Pretesting the Scanning setting with the actual election ballots, as delivered by the certified ballot printer, must be performed. When the first printed official ballots and/or test decks are received by the jurisdiction (prior to logic and accuracy testing), they should be tested on the ImageCast® Central system with the election project to confirm that the tabulator scanning parameter settings will work with the ballots as printed. With the variety of print methods used to print ballots, and the substantial variation in the types of printing presses, a small batch of ballots, numbering between 50 and 100 ballots (sampled throughout the ballot ® types and styles) should be tabulated with one of the ImageCast Central tabulators that have been defined in the elections project (usually the absentee 6/18/2024 147 Version: 5.19::4 Chapter 4 - Election Set-up and Definition tabulation unit). These ballots will not be marked (although they can be if they are test deck ballots) to confirm that they will not misread and that un-voted voting positions do not read as ambiguous marks. To run this test, perform the following steps: 1. Setup, load, and prepare your ICC tabulator for use as per the procedures outlined below. a. On the Configuration menu, click the Scan Options button. b. With the Scan Options dialog box displayed, select the option to “Stop Scan on" on ambiguous marks. 2. Return to the Scanning menu and start scanning ballots. a. In order for the test to pass, there should not be any interruptions in the scanning process due to ambiguous marks. b. If the scanner is stopping due to ambiguous marks, troubleshoot the scanner (see section F.2.1.1“Ambiguous Errors”). 4.5.1.3 Test Decks Required for Logic and Accuracy Testing Test decks are generated either manually from unmarked ballots, automatically ® using the Democracy Suite test deck generator utility, or by a combination of the two methods. Ensure you test for the handling and reporting of exception ballots (blank, over-voted, write-in, error, etc.) as required by the elections code. While test decks can be created at the jurisdiction on the EMS ballot printer, actual Official Ballots produced by the CA-certified ballot printer should also be included in the test. A control sheet should be created that summarizes the total results for the test decks prior to beginning the logic & accuracy testing. Pre-marked test decks should be supplied by the jurisdiction's selected certified ballot printer. This ensures that the exact paper, ink, and print process for use on election day are being tested. There are two distinct levels of test decks: “Ballot Level” and “Tabulator Level”. The meanings of the different levels of test decks will become clear when executing the procedures below. 1. Establish Ballot-Level test decks and VoteSims for each ballot style: Each ballot style will have its own test deck, called a “Ballot Level” test deck. For a given ballot style, each and every voting space on that ballot style must be tested. Therefore, the number of ballots in the “Ballot Level” test deck will depend on the number of candidates that appear on that particular ballot style. Once the “Ballot Level” test decks have been created for each of the ballot styles, conduct tabulator and manual counts in order to determine the results for each “Ballot Level” test deck. 2. Establish “Tabulator Level” test decks and VoteSims for each tabulator: Each tabulator will also have its own test deck called a “Tabulator Level” test 6/18/2024 148 Version: 5.19::4 Chapter 4 - Election Set-up and Definition deck. The test deck for a given tabulator will simply be the combination of the “Ballot Level” test decks for each of the ballot faces that the tabulator is programmed to accept. If applicable, the “Tabulator Level” test deck for a given tabulator should include ballot styles that the tabulator is programmed to reject in order to ensure that it has been correctly programmed to do so. For example, if the tabulator is programmed to read Ballot Style 1 of 80, another style (of the 80) should be scanned to verify that the machine is programmed to reject them. The results for each of the “Tabulator Level” test decks can be determined by manually adding together the results from each of the “Ballot Level” test decks that comprise the particular “Tabulator Level” test deck. 4.5.1.4 Scanning the USB Media using Windows Defender To scan a USB media device for viruses, follow these steps: 1. On the Reformatting workstation, insert the USB media into the USB port. 2. On the Windows Explorer dialog, in the left-hand pane, navigate to the USB media, right-click and then select Scan with Windows Defender. 3. On the Windows Defender Security Center dialog, choose Custom scan, and then click Scan now. 4. Safely remove the USB media. 5. Close any open dialogs. 4.5.1.5 Backup of Election Project Ensure that the EMS Administrator has backed up the Election Project (see section 12.2.1“Backing Up an Election Project”) prior to starting the Logic & Accuracy Test. The project package created during this backup procedure must be manually copied and saved to a dedicated and safe location. The folder where the project is saved should be distinctly named in order to differentiate it in the future. NOTE: Do not rename the .zip or .sha files that are created for the project package backup. 4.5.2 Logic and Accuracy Test Procedures Once the system has been fully configured, and as soon as possible after receipt of the first set of official election ballots from the printer, the jurisdiction must conduct formal logic & accuracy testing in order to confirm that the system has been correctly configured, and that all components are functioning properly. The process of logic & accuracy testing is described generally, and then more specifically in the sections to follow. This section includes information about the following: 6/18/2024 149 Version: 5.19::4 Chapter 4 - Election Set-up and Definition ® • ImageCast Central Logic & Accuracy Testing Procedure ® • ImageCast Evolution Logic and Accuracy Test Procedures ® • ImageCast Precinct 2 Logic and Accuracy Test Procedures ® • ImageCast X Logic and Accuracy Test Procedures • ImageCast X Vote Simulator • Mobile Ballot Production Logic and Accuracy Test Procedures • Adjudication and Post-Election Processing Logic and Accuracy Test Procedures Logic & Accuracy Testing is described in the subsections below. This procedure ® assumes that the EMS Adjudication application is a part of the Democracy Suite configuration and workflow. • Logic & accuracy testing should include the same steps as if running a real election. • If any vote discrepancies or errors are encountered during this process, the ballots and the procedure must be reviewed as human error is the most likely the cause. Otherwise, the administrator is informed immediately. Once the problem has been corrected, repeat the entire logic & accuracy testing procedure for the selected tabulator(s). • If there are no errors or discrepancies, sign and date the forms certifying that the logic & accuracy testing has been conducted successfully. These forms should be retained, along with the test decks, as part of the test documentation records for the election. • The administrator must back up all results following the successful logic & accuracy test. • Finally, each of the tabulators are re-zeroed and the results database is purged in order to delete the logic & accuracy results from the system prior to the actual election. • Once the logic & accuracy testing is complete and the system has been re- zeroed, all components of the system must be stored in a secure location until the election (or until the first early voting opportunity) in order to ensure that they cannot be accessed or tampered with. NOTE: The Logic & Accuracy Test is described in the subsections below. The ® testing process involves detailed procedures for the ImageCast Evolution, ® ® ImageCast Precinct 2, and ImageCast Central tabulators, post-election 6/18/2024 150 Version: 5.19::4 Chapter 4 - Election Set-up and Definition processing and adjudication, as well as results processing in the Results Tally and Reporting (RTR) application. ® 4.5.2.1 ImageCast Central Logic & Accuracy Testing Procedure ® This section describes the Logic & Accuracy Test procedure for the ImageCast Central tabulators. The procedure consists of loading each set of ICC election files and testing these election files by scanning test decks and verifying the results reports. The election files for each ICC tabulator are loaded, the test decks scanned, adjudicated, and the results uploaded to EMS RTR. The testing procedure is repeated for each of the ICC tabulators defined in the project. After testing is complete, the test results are archived. NOTE: Make sure to test every tabulator that is defined in the election project (including any spare tabulators). 1. Before you begin, ensure that the ICC workstation and scanner are powered on. 2. The election administrator will need to copy sets of ICC election files from the EMS server to the ICC workstations (see section 3“Click Apply, and then click OK to close.”) and prepare each set of election files to be loaded on ICC workstations. 3. Ensure that the iButton security key for the loaded election files has been programmed and connected to the ICC workstation. 4. The election administrator should ensure that the election files to be tested have been imported into the ICC application. 5. Open ICC application (see section 7.4“Loading an Election to the ® ImageCast Central System”). 6. Generate the Zero Report by selecting Review, and then clicking Create Report. The Zero Report will be available as long as the tabulator's results are completely zero. 7. Set the secondary path to the location where the ICC tabulator should save results to the local network. If you are using Automatic Results Loading, then the secondary path should be set to the following location on the EMS Server’s NAS: EMSSERVER\NAS\<ELECTION PROJECT NAME>\CentralResults. If you are not using Automatic Results Loading and are saving results locally, set 6/18/2024 151 Version: 5.19::4 Chapter 4 - Election Set-up and Definition the Secondary Path to the location/drive where the results files and images should be saved. 8. Tabulate the pre-marked test deck of ballots onto the ICC. 9. Be sure to test all tabulators defined in the election. Users can switch between loaded tabulators by clicking the Configuration icon, selecting Project Management, and then selecting the desired tabulator and clicking Load. 10. Close the tabulator by clicking on the Configure button, then clicking the Close button. A confirmation message will display. Click Confirm. 11. Generate the Results Report by selecting Review, and then selecting Create Report. From the Report Type drop-down that displays, select Results Report. 12. Complete the test for each ICC tabulator defined in the election project. 13. For each tabulator tested confirm that the tabulator-level result reports match the expected results from the pre-marked test deck. 14. Exit the ICC application by clicking the QUIT button. The confirmation dialog will appear. Click OK to exit the application. 15. Have the Administrator back up the local results from each ICC tabulator. 16. Open the RTR application. 17. Open the appropriate Election Project by selecting Election Project, and then selecting Open Project. Select the appropriate election project and click OK, then enter your login credentials. 18. Load the results files (see section 8.2.1“Loading Results from Removable Media Management”), audit log files and result images (if enabled and required) from the ICC tabulators into the RTR application. The results for tabulators that have the secondary path set to the EMS NAS will be loaded by starting Automatic Results Loading in RTR. For tabulators that have an alternative secondary path, results will need to be loaded manually. 19. Validate and publish results. 20. Create the Election Summary Report. 21. Confirm that the results from the election summary report from RTR match the tabulator summary reports and the expected test deck results. 6/18/2024 152 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 22. Review a subset of Audit Marked images in order to confirm that ballot image files are clear and readable and to verify that the system is interpreting the individual ballots correctly. ® 4.5.2.2 ImageCast Evolution Logic and Accuracy Test Procedures ® This section describes the Logic & Accuracy Test procedure for the ImageCast Evolution tabulators. The procedure consists of loading election files to an ICE tabulator and testing of these election files by scanning ballots and verifying the reports in RTR. This procedure is repeated for each ICE tabulator programmed in the election project. NOTE: Initially, the results will be loaded into RTR with Skipped Adjudication option selected and the election summary report will be run (simulating election night reporting). Then, if using adjudication, the originally imported results for such tabulators will be reset in RTR. The ballots will then be adjudicated and canvass reports will be produced. After testing is complete, the CF cards used will be re-zeroed and stored for later use in official ballot processing. 1. In EED, create the CF cards and corresponding iButton for each ICE to be tested. 2. Insert the memory card containing the election project into the CF1 card slot of the ICE tabulator, and the initialized backup memory card into the CF2 card slot on the tabulator. 3. Power up the ICE tabulator by lifting the LCD monitor into the operating position. 4. When prompted by the LCD screen, apply the iButton Security Key, enter the appropriate password when prompted, and then press OK. 5. Confirm that the date and time are displayed correctly on the lower left section of the ICE LCD screen. 6. Open the polls by pressing the Open Poll button. 7. Tabulate the pre-marked test deck of logic & accuracy testing ballots into the ICE tabulator by feeding the test deck and then return here to continue with next steps below. NOTE: Please note and confirm the tabulators' handling of any exception ballots per DCF/MBS that were set according to jurisdiction's procedures. 8. Start an accessible voting session by applying the iButton to access the Poll Worker Menu. From the Poll Worker Menu select Accessible Voting and press the Start button. Vote a predefined voting pattern for every language defined in the election project. Be sure to test every candidate position at least once, and verify that the audio that plays matches the visual content displayed. 6/18/2024 153 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 9. After all ballots have been tabulated and an accessible voting session has been completed, insert the iButton security key and close the polls. 10. Allow the two result tapes to print and confirm that you do not need another copy. 11. Power down the unit by pressing the Shut Down icon at the top-right corner of the screen. 12. On the right side of the ICE, open the CF1 and the CF2 card slot doors, and remove both cards from the tabulator. Place both cards in the envelope provided. These cards will be used for tally in RTR. 13. For each tabulator tested, confirm that the tabulator-level result reports match the expected results from the pre-marked test deck. 14. Open the RTR application. 15. Open the appropriate election project by selecting Election Project from the top of the screen, and then select Open Project. Select the appropriate election project and click OK, then enter your login credentials. 16. Load the results files, audit log files, and result images by selecting Actions from the top menu, then selecting Removable Media Management. Ensure that Skip Adjudication is checked, then click the Start Loading button. Insert the CF cards, one at a time, into the CF card reader until all results are loaded. 17. Validate and publish results files. 18. Create the Election Summary Report. 19. Confirm that the results from the election summary report from RTR matches the tabulator summary reports and the expected test deck results. 20. Review a subset of Audit Marked images in order to confirm that ballot image files are clear and readable and to verify that the system is interpreting the individual ballots correctly. ® 4.5.2.3 ImageCast Precinct 2 Logic and Accuracy Test Procedures NOTE: Make sure to test every tabulator that is defined in the election project (including any spare tabulators defined). ® This section describes the Logic & Accuracy Test procedure for the ImageCast Precinct 2 tabulators. The procedure consists of loading election files to an ICP2 tabulator and testing of these election files by scanning ballots and verifying the reports in RTR. This procedure is repeated for each ICP2 tabulator programmed in the election project. NOTE: Initially, the results will be loaded into RTR with the Skipped Adjudication option selected and the election summary report will be run (simulating election night reporting). Then, if using adjudication, the originally 6/18/2024 154 Version: 5.19::4 Chapter 4 - Election Set-up and Definition imported results for such tabulators will be reset in RTR. The ballots will then be adjudicated and canvass reports will be produced. After testing is complete, the SD cards used will be re-zeroed and stored for later use in official ballot processing. 1. In EED, create the SD cards and corresponding iButton for each ICP2 to be tested. 2. Insert the memory card containing the election project into the SD1 card slot of the ICP2 tabulator, and the initialized backup memory card into the SD2 card slot on the tabulator. 3. Power up the ICP2 tabulator by using a pen or stylus to press in the Power button to the left of the three LED lights next to the Administrator port door and hold for 2-3 seconds. A solid green light will display on the front left of the scanner. 4. When prompted by the LCD screen, insert the iButton Security Key and enter the appropriate password. Confirm that the date and time are displayed correctly on the lower left section of the ICP2 LCD screen. 5. Open the polls by selecting the Open Polls button from the Poll Management screen. 6. Prepare the ICP2 for scanning by activating the Standard Voting session. 7. Tabulate the pre-marked test deck of logic & accuracy testing ballots into the ICP2 tabulator by feeding the test deck and then return here to continue with next steps below. NOTE: Please note and confirm the tabulators' handling of any exception ballots per DSD/MBS that were set according to jurisdiction's procedures. 8. After all ballots have been tabulated, apply the iButton security key to the receptacle and enter the PIN. From the Main Menu screen that displays, select Poll Management, then select Close Poll. 9. Enter the PIN, select the Print button to print a results report and press Next. Enter the number of copies of the report to print (at least 1) and tap Next. If prompted to print the Write-in Report, select Don’t Print. From the Close Poll Confirmation screen, press Confirm. 10. Allow the two result tapes to print and confirm that you do not need another copy. 11. Power down the ICP2 by selecting Utilities from the Main Menu then select Power Down. Press Confirm. 12. Open the SD1 and the SD2 card slot doors, and remove both cards from the tabulator. Set the cards aside, noting which tabulator they were retrieved from. These cards will be used for tally in RTR. 6/18/2024 155 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 13. For each tabulator tested, confirm that the tabulator-level result reports match the expected results from the pre-marked test deck. 14. Open the RTR application. 15. Open the appropriate election project (see section 8.1.2“Open Project”) and enter your login credentials. 16. Load the results files (see section 8.2.1“Loading Results from Removable Media Management”), audit log files and result images (if enabled and required) from ICP2 tabulators, ensuring that adjudication is skipped. Once all result files are uploaded, return here and continue with the next step. 17. Validate and publish (see section 8.2.4“Validate and Publish Results”) results files in the RTR application. 18. Create the Election Summary Report (see section 8.2.5“Election Night Summary Report - Election Day Report”). 19. Confirm that the results from the election summary report from RTR matches the tabulator summary reports and the expected test deck results. 20. Review a subset of Audit Marked images in order to confirm that ballot image files are clear and readable and to verify that the system is interpreting the individual ballots correctly. 6/18/2024 156 Version: 5.19::4 Chapter 4 - Election Set-up and Definition ® 4.5.2.4 ImageCast X Logic and Accuracy Test Procedures NOTE: Make sure to test every tabulator that is defined in the election project (including any spare tabulators defined). This section describes the logic and accuracy testing procedure for the ICX Ballot Marking Devices. The procedure consists of loading election files to an ICX, printing ballots, and testing by scanning the printed ballots on an ICC, ICE, or ICP2 and verifying the reports in RTR. This procedure is repeated for each ICX defined in the election project. 1. Program the USB media and corresponding Smart Cards for the ICX to be tested. 2. Program the Technician Smart Card for accessing the technician menus. 3. Program the Poll Worker Smart Card for logging into the ICVA application and accessing the poll worker menus in the ICX. 4. Power up the ICX by pressing the power button on the back side of the device. 5. Insert the Technician smart card and enter the appropriate PIN. 6. When prompted, confirm or modify the date and time. 7. Insert the USB media containing the election project into the available USB card slot of the ICX tabulator and load election files. 8. Open the polls by pressing the Open Poll button from the Poll Administration menu. ® 9. Log into the ImageCast Voter Activation (ICVA) application by inserting the Poll Worker Smart Card on the ICVA workstation and inputting the appropriate PIN. If activation codes have not been imported, see section D.4“Importing ® Activation Codes to the ImageCast Voter Activation Application” 10. Program a voter activation Smart Card by inserting a Voter Card into the ICX, selecting the desired Activation Code, and then pressing Activate Voter Card. 11. Use the voter activation Smart Card to produce marked ballots according to the predefined pattern for Logic & Accuracy Testing. Repeat the process as many times as there are ballots to be marked. NOTE: Please note and confirm the tabulators' handling of any exception ballots per MCF that were set according to jurisdiction's procedures. 12. Program a voter activation Smart Card with Accessible Voting Session enabled and vote a predefined voting pattern for every language defined in the election project. Test every candidate position at least once, and verify that the audio message matches the visual ballot display. 6/18/2024 157 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 13. Insert the Poll Worker Smart Card, close the poll (if desired) and power down the unit by selecting the Power Off option at the bottom right of the poll worker of technician menus. 14. Tabulate all the ballots printed by the ICX Ballot Marking Devices using ® ® ® either the ImageCast Evolution, ImageCast Precinct 2, or ImageCast Central tabulator(s), depending on jurisdictional configurations. 4.5.2.5 ImageCast X Vote Simulator The Vote Simulator is a Logic and Accuracy test created with the purpose of verifying that the pre-defined patterns are read and tabulated correctly. In order to run the Vote Simulator a valid test pattern file is required. ® The Vote Simulator is to be run before the ImageCast X machine is put in production on the day of the election. ® The simulation is performed by loading an XML file and ImageCast X election files provided by Dominion Voting. Should there be a requirement for personalized data, the XML file can be edited manually. The following steps need to be taken in order for the Vote Simulator to perform a valid test: 1. Power up the ICX tabulator by pressing the power button on the back side of the device. 2. Insert the USB media containing the VoteSim .XML files. 3. To copy the necessary files from the USB media, log in as a Technician by inserting the Technician smart card. The Administrator Login screen displays, allowing the technician to enter their PIN. 4. In The election configuration files on USB drive dialog, the ® technician chooses the needed file and copies the data to the ImageCast X device. 6/18/2024 158 Version: 5.19::4 Chapter 4 - Election Set-up and Definition a. Press Select. Figure 4-1: USB Drive containing Election Files and the Copy/Cancel Election Files Dialog b. On the Confirm dialog, press Copy. Having completed this portion, decrypt the election files. To decrypt the election files: 1. Enter the Poll Worker smart card and enter the PIN. The election file decryption begins. When completed, the Poll Administration panel is accessible to the Poll worker. 2. Select the appropriate Tabulator. Only one Tabulator should be chosen. 3. Once the Tabulator validation is completed, press Open Poll. 4. To confirm the selection, on the Info dialog, press Yes. Once the Poll is Open, the Poll worker will be prompted to Print the Zero report in ® order to confirm that the ImageCast X device is prepared for the Vote Simulation, and that no redundant files remain on the device. To print the zero report: 6/18/2024 159 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 1. On the Poll Administration screen, press Print zero report. The Print zero report dialog appears. 2. Remove the Poll worker card and insert the Technician card and PIN. After the Technician Administration screen is presented, a Warning dialog displays advising the user that the Administrative menu is unavailable while the Poll is open. NOTE: In order to proceed the Poll MUST remain OPEN. All options except Hardware Details, Brightness, the Hardware Test and the Vote Simulator are grayed out and cannot be selected. 3. Press Vote Simulator. The Voting Test screen displays. On the Voting Test screen, the user has the following options to choose from: • Print votes on the VVPAT - ON/OFF - default OFF • Animations enabled - ON/OFF - default OFF • View ballots being marked - ON/OFF - default OFF NOTE: The available options are enabled depending on the Automated Test Deck file provided for the testing. If the View ballots being marked box is checked, the ballots will be marked on-screen, if the Test Deck file supports it. If the View ballots being marked box is unchecked, a Progress bar displays. NOTE: Be advised that the settings available on the Vote Simulator start screen are independent from the MCF, so any settings for the Vote Simulator can be manipulated from the Vote Simulator start screen exclusively. To start the Vote Simulator Test: 1. Press the Load Test Pattern. 2. In The test configuration files in USB drive dialog, navigate to the XML file needed. ® The XML files are copied over to the ImageCast X. The XML files are then validated, and the Technician can proceed to set the Test parameters as needed. NOTE: "Number of repetitions" refers to the whole pattern. 6/18/2024 160 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 3. Remove the Technician card and insert the Voter card. The Vote Simulation Test can commence. NOTE: The Voter card has to remain inserted through the duration of the entire test. If you decide to end the test, prior to completion, simply remove the Voter card.The Vote Simulator Superman is available for both the DRE and BMD modes of operation. Should an issue occur while printing the BMD Paper Ballot, the User will receive the following error: "Check the printer. If the ballot has been printed, please discard it, otherwise, press Cancel on the printer control panel." If the ballot does not exit the printer once this error message is shown, the user is advised to check for potential paper jams, and to resolve the issue accordingly. 4.5.2.6 Mobile Ballot Production Logic and Accuracy Test Procedures Loading Election Files The ballot definition data will be exported from Election Event Designer to a USB media device and then transferred to a Mobile Ballot Production (MBP) workstation. To export a project data file: 1. Insert a clean USB media into a USB port. 2. Expand the Election Project menu on the top toolbar, click Export, and then select Mobile Ballot Production Project. The Export MBP Data dialog opens. NOTE: If an External ID warning dialog opens, click OK. 3. On the Export MBP Data dialog, complete the following: • Ensure the Include ballots in the archive and Include ballots with stubs checkboxes are selected. • Select the Protect the archive with a password checkbox. • Enter a password and re-enter the same password. • Click Continue. • On the MBP Export Completed dialog, click OK. 4. Open Windows Explorer and complete the following: • Navigate to \\emsserver\NAS\<current project>\MBP Exports folder. • Copy the folder This folder contains a .zip and .checksum file. • Paste the folder into the USB location. 6/18/2024 161 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 5. Safely remove the USB media from the EMS Client Workstation. To copy the project data file: 1. On the MBP Client Workstation, insert the USB media (from EMS Client Workstation) into a USB port. 2. Open the MBP application. 3. From the Main Menu screen, click File and then select Import. 4. If prompted for a password, enter the password and click OK. 5. On the Set up a new project dialog, complete the following: • In the Ballots info archive field, click Browse, navigate to the USB folder location and select the .zip file (exported from EED), and then click Open. • In the Archive password field, enter the password (created in the Export MBP Data dialog). • In the Project destination path, click Browse and select an empty folder, and then click OK. • In the Create new election project with name field, enter a name for your election project, and then click Load. This could be the same project name as saved in EED. 6. On the Import Result dialog, click OK. The election files are loaded and the project opens. Configuring the Printer This section will specify the location to store Ballot artwork, select the default printer and configure the printer settings. To specify the ballot artwork location: 1. From the Open project screen, click File, and then select Ballot Source. 2. On the Ballot Source Location dialog, navigate to the file location and click OK. To specify the default printer: 1. From the main menu, click File and then select Default Printer. 2. On the Default Printer dialog, select the printer from the drop-down and click OK. 3. If the default printer is changed, click OK. To configure the printer settings: 1. On the main menu, click File and then select Printing Configuration. 6/18/2024 162 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 2. On the Printing Configuration dialog, complete the following: • If you want to include a sample ballot watermark on the print-out, select the Sample Ballot checkbox. • Specify the number of copies to print for the selected ballot. 3. On the Printing Configuration dialog. Click Save to save printing settings. Printing Ballots When the project is created and configured, the application is ready to print ballots. The main screen will list all ballots that are available for printing. The list contains a column which indicates the number of times a particular ballot has been printed. To print ballots: 1. From the main menu, select a ballot from the list, and then click Print. 2. On the Print Settings dialog, complete the following: • Verify that the Document Height value is black. • Click Preferences and complete the following on the Printer Preferences dialog: • If the Document Height value is red, select the correct ballot paper size from the size drop-down. If the correct paper size is not available, refer to the Printer User Manual for detailed instructions on creating a custom size. • Set double-sided printing to Long Edge. • Click OK. • On Print Settings dialog, click Print. If multi-card ballots are being printed, you must click Print on each open Print Settings dialog. Generating Reports The Print report, Audit report and Invalid Files report can be stored in various formats or printed using the controls shown immediately above the report itself. To view Print Report: 1. From the main menu, click Print Report. 2. On the Print Report dialog, select Precinct information and click View Report. 6/18/2024 163 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 3. To save the report, click the Export icon, and select the file type, select the location where the report is saved, and then click OK. To view the Audit Report: 1. From the main menu, click Audit Report. 2. On the Audit Report dialog, select the date range, Action information, and then click View Report. 3. To save the report, click the Export icon, and select the file type, select the location where the report is saved, and then click OK. 4.5.2.7 Adjudication and Post-Election Processing Logic and Accuracy Test Procedures This section describes the procedure for testing the Adjudication of ballots. 1. Open the RTR application. 2. Open the appropriate Election Project by selecting Election Project, and then Open Project. Select the appropriate election project, press OK, and enter your login credentials when prompted. 3. From the left navigation pane, select Results Files. 4. Click the Search button (without applying any search criteria) to see all result files loaded into the election. 5. Use the Sort functionality to identify result files that are in status Skipped Adjudication. 6. Select/highlight all result files and click Reject. 7. Click Reset. 8. Click Allow Adjudication, which will enable adjudication to be performed on those result files. This step require that images are already loaded. 9. The Adjudication Administrator must log into an EMS workstation and start an Adjudication session using the settings appropriate for the jurisdiction. 10. Adjudication User(s) should log into Adjudication workstations and adjudicate the ballots presented for adjudication. 11. The Adjudication Administrator may submit batches as they are completed by adjudication users. When all batches have been adjudicated the Administrator should generate and save any reports necessary to be saved with the Logic and Accuracy records. 12. Validate and publish results files. 13. Run the Election Summary Report in RTR. 6/18/2024 164 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 14. Compare and verify that the Election Summary Report matches the expected results. 4.5.3 Logic and Accuracy System Test Acceptance Criteria and Completeness Logic and Accuracy testing is only complete when all results are accurate. Any errors found should be corrected, and the appropriate tests should be repeated until accurate results are achieved. To verify the completeness of the System Logic & Accuracy Test, confirm the following: • the tabulator-level result reports match the expected results from the pre- marked test decks. • exception ballots are properly handled by the tabulator per the DCF/MBS settings. • the individual tabulator reports from RTR match the tabulator level result reports. • the summary report for each counting group defined in the Election Project matches the sum of all individual tabulator level reports for that group. • the Election Summary report after the adjudication of ballots matches the expected results. ® • the ballot image files are clear and readable from the ImageCast Central, ® ® ImageCast Evolution, and ImageCast Precinct 2. • the tabulator “Counting Groups” are configured correctly and according to the jurisdiction's preference. Verifying items above is imperative for obtaining the correct X of Y values in percentage of precincts reported. 4.5.4 Backing up the Logic and Accuracy Test Results Before resetting the system for election day, make sure that the EMS Administrator has backed up the results from the entire system. This includes the following: 1. A backup of the Election Project containing the results from the executed Logic & Accuracy Test. The project package created during this backup procedure must be manually copied and saved to a dedicated location. NOTE: Do not rename the project package. ® ® 2. ImageCast Evolution and ImageCast Precinct 2 tabulated results will be backed up within the election project package, however, jurisdictions may choose to keep additional backups by copying results from the CF cards and 6/18/2024 165 Version: 5.19::4 Chapter 4 - Election Set-up and Definition storing those results separately. CF cards and SD cards need to be clearly labeled so that they can be returned to their respective ICE or ICP2 units for use during Early Voting and/or Election Day voting. 3. Generate a backup of all ICC results and scanned image files from the Logic & Accuracy Test by exporting the batches of results and images from the ICC's Review screen. 6/18/2024 166 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 4.5.4.1 Retention and Documentation of Test Materials ® Reports generated by products within the Democracy Suite product line during logic and accuracy testing should be retained along with test decks, and any supplementary testing materials, for the retention period required by California law. Place all documentation in envelopes and/or boxes. Seal, initial, and date the envelopes and/or boxes, as required by California law. This retention period should take place in a secured location with access restricted to those designated ® by the jurisdiction. If the Democracy Suite system is used in a federal election, testing materials must be retained for a period of 22 months as required by federal ® regulation. A listing of the available reports on ImageCast Evolution can be found in Permanent Printed Reports (refer to I“Permanent Printed Reports”). A ® description of available reports on ImageCast Central is available in Section ® Producing Reports from the ImageCast Central System (see section ® 7.9.4“Producing Reports from the ImageCast Central System and Closing the Tabulator”). 4.5.5 Clearing Logic and Accuracy Test Results Once Logic and Accuracy testing is complete, each tabulator is re-zeroed and the results database is purged to delete the logic and accuracy results from the system prior to the actual election 4.5.6 Re-zeroing the ICC Re-zeroing the tabulator clears the scanned ballots’ results and the tabulator’s history. Once completed, this process cannot be undone. To re-zero the ICC, follow these steps: 6/18/2024 167 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 1. From the left navigation pane, select Configure. See Figure4-2. Figure 4-2: ICC Configure screen - Close option 2. Under Tabulator State in the top-right corner of the Configure screen, select Close. A confirmation dialog displays notifying you that no further ballots can be scanned once the tabulator is closed, see Figure4-3. Figure 4-3: ICC Configure screen - Confirm Close Tabulator 6/18/2024 168 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 3. Click Confirm. 4. Enter Supervisor Mode by clicking the ‘Enter Supervisor Mode’ icon from the bottom left of the screen. The Password Required screen opens, see Figure4-4. Figure 4-4: ICC Supervisor Mode Password screen 5. Input the Supervisor PIN and then click Login. 6/18/2024 169 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 6. Under the Purge Results section to the right of the screen, click Re-Zero Results, see Figure4-5. Figure 4-5: ICC Supervisor Mode Configure screen - Re-Zero Results 7. A confirmation message will display. Click Confirm. The tabulator will re-zero. NOTE: The tabulator will need to be reopened prior to scanning regular ballots. 4.5.7 Re-zeroing the ICE If the election cards have been used for testing prior to the election day (during Logic and Accuracy testing procedure) then all the recorded results need to be set to zero. 1. On the poll worker Menu screen, press the Advanced Admin option. Depending on the configuration set in the MBS file, you may be asked to provide a username and password, or password only when entering the Advanced Admin menu. In addition, the MBS gives an option to omit the authentication. 6/18/2024 170 Version: 5.19::4 Chapter 4 - Election Set-up and Definition a. When prompted, enter the credentials (the poll worker's credentials are set in EMS EED client application). b. Press OK. 2. On the Advanced Admin screen, press the Re-zero button. 3. On the right-hand pane, press Re-zero. 4. On the Confirmation required screen, press OK to proceed. Figure 4-6: Re-zero Results Confirmation 6/18/2024 171 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 4.5.8 Re-zeroing the ICP2 Re-zeroing the tabulator resets the ballot counter to zero. When instructed to do so, re-zero the tabulator: 1. From the Main Menu screen, tap Poll Management. Figure 4-7: Main Menu screen 6/18/2024 172 Version: 5.19::4 Chapter 4 - Election Set-up and Definition The Please Enter Password screen appears. 2. Enter your password and tap Enter. The Poll Management screen appears. Figure 4-8: Poll Management screen 3. From the Poll Management screen, tap Re-Zero Tabulator. The Please Enter Password screen appears. 4. Enter your password and tap Enter. The Re-Zero Results Confirmation screen appears. Figure 4-9: Re-Zero Confirmation screen From the Re-Zero Results Confirmation screen, tap Confirm. The Ballot Counter field at the bottom left resets to zero and you are returned to the Main Menu screen. 4.5.9 Re-zeroing the ICX 1. Ensure the device is on. 2. Log in using a poll worker smart card. 3. Ensure the poll is closed. If the poll is not closed, select Close Poll. 6/18/2024 173 Version: 5.19::4 Chapter 4 - Election Set-up and Definition 4. Next to Public Counter, select ReZero. See Figure4-10. Figure 4-10: ICX - Re-zero option on Poll Administration screen 4.6 Election Observer Panel During the various phases of the election setup process, ranging from: • Central Count equipment programming and configuration • Central Count equipment logic and accuracy testing • Tabulation and ballot marking device programming and configuration • Tabulation and ballot marking device logic and accuracy testing An Election observer panel may be present for activities. This panel may include: • Representatives from qualified political parties • Representatives from legitimate citizens or media organizations The county elections officials may limit the number of observers, as needed. 4.7 Hardware Maintenance and Preparation for Use After successful completion of a Logic and Accuracy test, election equipment must be properly prepared for an election day. After the preparation, the equipment is then securely stored, as per jurisdictional procedures. This chapter provides ® instructions on how to prepare the Democracy Suite equipment for an election. This section contains information about the following: 6/18/2024 174 Version: 5.19::4 Chapter 4 - Election Set-up and Definition ® • ImageCast Evolution Preparation ® • ImageCast Central Maintenance and Preparation ® • ImageCast Precinct 2 Preparation ® • ImageCast X Maintenance and Preparation 4.7.1 ImageCast® Evolution Preparation Load the CF cards into the tabulator and store the tabulator. 4.7.1.1Internal Battery Recharging In order to obtain maximum battery life, periodic maintenance of the internal back-up battery is important. It is therefore recommended that the internal back- up battery be charged for at least 12 hours every eight months when the unit is in power-off mode/storage. It is equally important to ensure that the internal battery is fully charged before the unit is deployed on Election Day. The Battery Status is indicated using visual indicators on the ICE side panel. To charge the battery, connect the unit to a standard 120V, 60Hz AC Power Supply and ensure that the Touchscreen LCD is in its horizontal position and the Service Switch in the ON position. 4.7.2 ImageCast® Central Maintenance and Preparation ® Maintenance procedures for the ImageCast Central scanner configurations can be found in the commercial, off-the-shelf product documentation. 4.7.3 ImageCast® Precinct 2 Preparation Load the cards into the tabulator and store the tabulator. 4.7.3.1 Internal Battery Recharging All lithium-ion rechargeable batteries have a limited life and gradually lose their capacity to hold a charge over time, whether used or unused. In order to obtain ® maximum battery life, periodic maintenance of the ImageCast Precinct 2’s 6/18/2024 175 Version: 5.19::4 Chapter 4 - Election Set-up and Definition internal backup battery is highly recommended. If the battery is not periodically charged as recommended, the battery cells will fully discharge over time, possibly causing irreparable damage to the battery and its capacity to hold a full charge. ® To obtain maximum battery life from the ImageCast Precinct 2 internal lithium- ion battery, it is recommended that: • The batteries are charged for at least 6 hours, to full capacity, before placing the units in storage. • The batteries are charged for at least 6 hours, to full capacity, every four (4) months while the unit is in power-off mode or storage. The units may remain connected to AC power at all times, if desired. This should not damage the battery or reduce its lifespan. • The storage and operating temperature is as cool as possible. Lithium-ion batteries degrade faster if stored or used at higher temperatures. Maintaining a storage temperature below 68 F/20 C will maximize the recoverable capacity of the battery. The operating temperature of the ICP2 should not exceed 104 F/40 C. • For tracking and to maintain a recharging schedule, please note on the unit the date charged. To charge the battery, plug the tabulator into a standard 3-prong 115/120 VAC 50/ 60Hz wall outlet via the supplied 20VAC Power Adapter. The unit can be charged while powered down. Battery levels can be checked by pressing and quickly 6/18/2024 176 Version: 5.19::4 Chapter 4 - Election Set-up and Definition releasing (less than a second) the Power ON/OFF pushbutton at the rear of the tabulator. The Power Status LEDs at the front of the tabulator will flicker/blink in one of the following patterns: System power, combination of green and amber: Running from external Solid green power, battery present Running form the Solid amber battery Running from external Flashing green / amber power, NO battery present Table 4-2: System Power Battery status, orange: Fullycharged(ticklecharge Lit all the time mode) Charge state <25% One flash and a pause Charge state 25% to <50% Two flashes and a pause Charge state 50% to <75% Three flashes and a pause Charge state 75% to Four flashes and a pause <100% Power alarm Fast flashing Table 4-3: Battery status 4.7.4 ImageCast® X Maintenance and Preparation ® The ImageCast X does not require any software or preventative periodic maintenance tasks such as database performance analysis, software backup, or database tuning. However, it is recommended to periodically execute each of the following: • BMD printer cartridge removal/replacement/storage (refer to 4.7.4.1 “BMD printer cartridge removal/replacement/storage”) 6/18/2024 177 Version: 5.19::4 Chapter 4 - Election Set-up and Definition • ICX Internal Battery Recharging (refer to 4.7.4.2“ICX Internal Battery Recharging”) For more details, please refer to the SID-21V-Z37-A1R User Guide. 4.7.4.1 BMD printer cartridge removal/replacement/storage For proper printer cartridge removal, replacement and storage, please consult the manufacturer user guide for the corresponding printer. • HP LaserJet Pro M402dne - http://h10032.www1.hp.com/ctg/Manual/ c04639074 4.7.4.2 ICX Internal Battery Recharging In order to obtain maximum battery life, periodic maintenance of the internal back-up battery is important. It is therefore recommended that the internal back- up battery is charged for 4 hours every 6 months when the unit is in power-off mode/storage. It is equally important to ensure that the internal battery is fully charged before the unit is deployed on Election Day. The Battery Status is indicated using visual indicators once the ICX is powered up. To charge the battery, connect the unit to a standard 120V, 60Hz AC Power Supply and wait for the device to power up. Insert Technician Smart Card and enter the corresponding PIN. Once the Technician menu is available, select “Power off” and wait for the device to power down. 4.8 Physical Security of Equipment ® Once the system has been purged of L&A results and the ImageCast Evolution, ® ® ImageCast Precinct 2, and ImageCast X maintenance and preparation has been completed, all equipment needs to be physically secured in final preparation for Election Day voting (refer to H.2“Physical Security” for details about these security procedures). 6/18/2024 178 Version: 5.19::4 Chapter 5 - Early Voting Procedures CHAPTER 5: EARLY VOTING PROCEDURES 5.1 ImageCast® Evolution ® ® Democracy Suite EMS allows for the programming of specific ImageCast Evolution tabulators for use “in-office” in Early Voting or in Vote Centers. Ballot tabulation for a specific precinct, a range of precincts, or all of the precincts in the ® election may be programmed. The setup and use of an Early Vote ImageCast ® Evolution tabulator is the same as use of an Election Day ImageCast Evolution tabulator as described in Chapter 9, with the exception that the tabulation will take place for a period longer than one day. ® NOTE: When powering up the Early Vote ImageCast Evolution for the first time, ® the Zero Report tape is printed. An Early Vote ImageCast Evolution is connected to many or all precincts and, therefore, may contain a very large number of Ballot IDs that would require many rolls of thermal printer paper in order to print the full report. You may be provided with an option to cancel/disable the printing of the report (see below for steps on how to use this functionality to avoid printing of the zero tape). An alternative to the printed report tape is accessing the Report on LCD screen through the Utility option from the Administrative Menu. To turn off tape printing, do the following: 1. When powering up Early Voting ICE, apply the iButton Security Key to the iButton Security Key receptacle when prompted to do so. 2. Enter the Administrator user name and password and once logged in. The Poll-worker Menu opens. 3. To open the Poll Management screen, press Open Poll. The following three options are available: • Poll Status • Print Zero Tape • Number of Copies to Print 4. To change the Print Zero Tape option from Print to Don’t Print, press Change. Pressing Change a second time will change the option back to Print. 6/18/2024 179 Version: 5.19::4 Chapter 5 - Early Voting Procedures Depending on the size of the election and the number of ballot styles an Early Vote ® ImageCast Evolution is handling, it may be impractical to close the polls and power down the Early Vote tabulator after the end of each Early Voting day due to the length of time it takes to load election files on the tabulator during the power up process. If this is the case, the Poll should be closed at the end of the day, ® however, the ImageCast Evolution tabulator should stay turned on. After the Poll has been closed (refer to 6.7.1“Closing the Polls on ICE”), the ® Administrator should physically secure the ImageCast Evolution tabulator as per jurisdiction’s procedure, until the start of the next day, when the tabulator is taken out of the secured area and the Poll is re-opened on the tabulator to ® continue with the operation. In case your Early Voting ImageCast Evolution tabulator is handling the number of ballot styles which allows the tabulator to load the election in a reasonable amount of time, then the procedure for operating an ® Early Vote ImageCast Evolution is to suspend voting by shutting down the tabulator at the end of the day and restart the tabulator when voting resumes. To suspend voting: 1. Apply the iButton Security Key to access the Administrative Menu. 2. Enter the Administrative user name and password. 3. In the Administrative Menu, press the circular power button icon in the top right corner of the screen and press Shut Down. 4. This will initiate the countdown until the machine has fully powered down. 5. Close the privacy screen flaps, and place the LCD monitor in the horizontal storage position. 6. Replace the ballot box cover onto the ballot box, and then lock it and seal it until the next day. To resume voting: 1. Remove the seals, unlock, and remove the ballot box cover. 2. Lift up the LCD monitor into the vertical position and the unit will begin to power up. 3. Open the privacy screen flaps and insert the iButton Security Key when prompted to do so. 4. Enter the Administrative user name and password to get to the Administrative Menu screen. 5. In the Administrative menu, press Open Poll. 6/18/2024 180 Version: 5.19::4 Chapter 5 - Early Voting Procedures 6. A warning message alerts that the poll was already opened and that the results are not zero. Press OK. The tabulator will start printing a status report. Cancel the printing of the status tape if your election has a large number of Ballot IDs. 7. Confirm the Cancel option and the poll will be reopened. 8. In Administrative Menu, press Standard Voting and then press Start. ® 9. To confirm that the ImageCast Evolution is ready to resume scanning, press OK. ® Voting on the Early Vote ImageCast Evolution continues until the jurisdiction- defined Cut off time. At this point, the Administrator closes the poll (refer to ® 6.7.1“Closing the Polls on ICE”) on an Early Vote ImageCast Evolution.The ® Administrator will remove the CF cards from the Early Voting ImageCast Evolution tabulator and securely store them in a labeled and sealed transport container. The Election Official will then remove all of the ballots from both the Secondary and Main ballot box chambers of the ballot box and safely store them in clearly labeled bins/boxes. The ballots and the CF cards will be sent to the central location for processing if not located there in the first place. The results from Early Vote ICE tabulators will be imported, validated and published in RTR on Election Day. 5.2 ImageCast® Precinct 2 ® Democracy Suite® EMS allows for the programming of specific ImageCast Precinct 2 tabulators for use “in-office” in Early Voting or in Vote Centers. Ballot tabulation for a specific precinct, a range of precincts, or all of the precincts in the ® election may be programmed. The setup and use of an Early Vote ImageCast ® Precinct 2 tabulator is the same as use of an Election Day ImageCast Precinct 2 tabulator, with the exception that the tabulation will take place for a period longer than one day (refer to 6.4“Polling Place Procedures”). Depending on the size of the election and the number of ballot styles an Early Vote ® ImageCast Precinct 2 is handling, it may be impractical to close the polls and power down the Early Vote tabulator after the end of each Early Voting day due to the length of time it takes to load election files on the tabulator during the power up process. If this is the case, the Poll should be closed at the end of the day, ® however, the ImageCast Precinct 2 tabulator should stay turned on. After the ® Poll has been closed, the Administrator should physically secure the ImageCast 6/18/2024 181 Version: 5.19::4 Chapter 5 - Early Voting Procedures Precinct 2 tabulator as per jurisdiction’s procedure, until the start of the next day, when the tabulator is taken out of the secured area and the Poll is re-opened on the tabulator to continue with the operation. ® In case your Early Voting ImageCast Precinct 2 tabulator is handling the number of ballot styles which allows the tabulator to load the election in a reasonable amount of time, then the procedure for operating an Early Vote ® ImageCast Precinct 2 is to suspend voting by shutting down the tabulator at the end of the day and restart the tabulator when voting resumes. To suspend voting: 1. Apply the iButton Security Key to the security key receptacle to access the Administrative Menu screen. 2. Press Shut Down. This will initiate the countdown until the machine has fully powered down. 3. Replace the ballot box cover onto the ballot box, and then lock it and seal it until the next day. To resume voting: 1. Remove the seals, unlock, and remove the ballot box cover. 2. Enter the Administrative user name and password to get to the Administrative Menu screen. 3. In the Administrative Menu, press Open Poll. A warning message alerts that the poll was already opened and that the results are not zero. Press OK. ® Voting on the Early Vote ImageCast Precinct 2 continues until the jurisdiction- defined ‘Cut off’ time. At this point, the Administrator closes the poll on an Early ® Vote ImageCast Precinct 2.The Administrator will remove the SD cards from the ® Early Voting ImageCast Precinct 2 tabulator and securely store them in a labeled and sealed transport container. The Election Official will then remove all of the ballots from both the Secondary and Main ballot box chambers of the ballot box and safely store them in clearly labeled bins/boxes. The ballots and the SD cards will be sent to the central location for processing if not located there in the first place. The results from Early Vote ICP2 tabulators will be imported, validated and published in RTR on Election Day. 5.3 ImageCast® X ® Since ImageCast X is a Ballot Marking Device, the procedure is the same as for ® ImageCast X Election Day procedure (refer to 6.4“Polling Place Procedures”). 6/18/2024 182 Version: 5.19::4 Chapter 6 - Polling Place Procedures CHAPTER 6: POLLING PLACE PROCEDURES 6.1 Precinct Supplies, Delivery and Inspection Tabulator delivery and Election Day poll worker procedures should follow jurisdiction's practices in conformance with State Election Code. Sections starting from 6.1.1“Precinct Supplies” through to 6.2“Inspection and Polling Place Setup” provide some general information about delivery, supplies and handling ® ® ® procedures for ImageCast Evolution, ImageCast Precinct 2, and ImageCast X. ® For Election Day procedures for the ImageCast Evolution, see section 6.3.2“Opening the Polls on the ICE”, for ImageCast Precinct see 6.3.3“Opening the Polls on ICP2”, and ImageCast X see 6.3.1“Opening the Polls on the ICX”. 6.1.1 Precinct Supplies Prior to Election Day, the Precinct Board ensures the precincts have the correct supplies, and ensures that each Polling Place is ready for operation by performing the following tasks: • Checking all pads of paper ballots to ensure that ballot style identification numbers and precinct numbers (if used) printed on the paper ballots are correct. • Reporting any problems to the Election Official responsible for the election. • Having supplies necessary for the conduct of elections that shall be delivered as follows at Polling Places: • Paper ballots shall be in the quantity and manner required by the California Elections Code, as well as demonstrator ballots marked for demonstration use only. • Demonstration or voting instruction placards. • General purpose precinct supplies as provided in the California Elections Code. • Secrecy sleeves or envelopes, if ballots are printed on two sides. • Marking devices: Sharpie Fine Point Permanent Marker (Black), Staedtler Lumocolor Dry Safe Marker. • A certificate of packaging and sealing, in duplicate, together with a postage paid self addressed stamped business reply envelope, or postcard addressed to the responsible Election Official. • Sample ballots of each ballot style as required by the California Elections Code. • Seals and any other supplies and forms deemed necessary. 6/18/2024 183 Version: 5.19::4 Chapter 6 - Polling Place Procedures • Tables. • Power cords. • Machine/seal log. • Voter instructions. • Machine stickers. • Machine File Folders for Official Pre-LAT tapes. • For the HiPro scanner, a second set of Input Roller Assembly with hexagonal Pre-Input Roller and Separation Roller with higher resistance must be available for a quick change while scanning. This gives more flexibility to clean the roller set by another operator. 6.1.2 ImageCast® Evolution and Related Equipment The following facilities, furnishings, fixtures, and utilities are required at the ® polling place for the operation of the ImageCast Evolution: ® ImageCast Evolution Equipment ® ImageCast Evolution and power supply ® ImageCast Plastic Ballot Box ® ImageCast Ballots Compact Flash Memory Cards iButton Security Keys Sharpie Fine Point Permanent Markers ® Table 6-1: ImageCast Evolution Equipment 6/18/2024 184 Version: 5.19::4 Chapter 6 - Polling Place Procedures ® ImageCast Evolution Equipment Thermal Printer Paper Rolls Replacement Ink Cartridge Color-Coded Plastic Security Seals Audio Tactile Interface (ATI) L-R Paddles (Optional) Sip and Puff (Optional) Headphones Keys for Ballot Box 120V AC Power Wall Outlet ® Table 6-1: ImageCast Evolution Equipment 6/18/2024 185 Version: 5.19::4 Chapter 6 - Polling Place Procedures ® ImageCast Evolution Equipment Extension Cord (Optional) Election tape and Signage, as required Voting booths, as required ® Table 6-1: ImageCast Evolution Equipment 6.1.2.1 Delivery of Equipment The Warehouse Technician must perform a Pre-Election procedure for preparing the tabulators prior to shipment. Summary of these activities include, but may not be limited to, the following: 1. Completing the final inspection sheet (provided by the jurisdiction). 2. Entering the equipment serial number and software version of the Operating System in the daily log. 3. Placing keys (iButton Security Key and ballot box key) in an envelope with the final inspection sheet. 4. Removing the memory cards that were used for testing, then inserting the Memory Cards for the official election and securing as required by jurisdiction. NOTE: Verifying the Memory card is installed and coded for the specific location. 5. Checking the printer paper (replacing if needed). ® 6. Closing the ImageCast units, gathering the envelope containing final inspection sheet and keys. ® 7. Securing the ImageCast units for delivery to polling places or storage. 6/18/2024 186 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.1.2.2 Proper Handling and Moving Procedures ® The ImageCast Evolution tabulator is designed to be delivered to and from the polling site mounted to the ballot box. The ballot box has 2 lockable swivel wheels and 2 fixed wheels for easy handling and also has convenient handles on all 4 ® sides of the box to enable lifting or positioning as required. The ImageCast Evolution should be removed from the ballot box when in storage. The tabulator also has 2 hand grips located underneath the lengths of its sides to enable a two person lift if required for moving, installing, or removing from the ballot box. 6.1.3 ImageCast® Precinct 2 and Related Equipment The following facilities, furnishings, fixtures, and utilities are required at the ® polling place for the operation of the ImageCast Precinct 2: ® ImageCast Precinct 2 Equipment ICP2 and power supply ® ImageCast Plastic Ballot Box ® ImageCast Ballots SD Memory Cards iButton Security Keys Sharpie Fine Point Permanent Markers Thermal Printer Paper Rolls ® Table 6-2: ImageCast Precinct 2 Equipment 6/18/2024 187 Version: 5.19::4 Chapter 6 - Polling Place Procedures ® ImageCast Precinct 2 Equipment Color-Coded Plastic Security Seals Keys for Ballot Box Power Wall Outlet Extension Cord (Optional) Election tape and Signage, as required Voting booths, as required ® Table 6-2: ImageCast Precinct 2 Equipment 6/18/2024 188 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.1.4 ImageCast® X and Related Equipment The following facilities, furnishings, fixtures, and utilities are required at the ® polling place for the operation of the ImageCast X: ® ImageCast X Equipment ® ImageCast X HP LaserJet printer (with power and printer cable) Blank ballot paper Poll worker and voter activation Smart Cards Appropriate Replacement Toner Cartridge Color-Coded Plastic Security Seals Audio Tactile Interface (ATI) L-R Paddles (Optional) Sip and Puff (Optional) ® Table 6-3: ImageCast X Equipment 6/18/2024 189 Version: 5.19::4 Chapter 6 - Polling Place Procedures ® ImageCast X Equipment Headphones 120V AC Power Wall Outlet Extension Cord (Optional) Election tape and Signage, as required Voting booths, as required ® Table 6-3: ImageCast X Equipment 6.2 Inspection and Polling Place Setup After the units have been delivered to the polling place, the Poll workers will perform the following inspections: • Position the ballot box/tabulator in the appropriate location for use making sure that there is access to the AC power plug. • Inspect and record all seals are intact as per jurisdictional procedure. Specific Polling Place Setup Procedures will be provided to or by each respective jurisdiction. However, it is recommended that a two-person team be available for ® setting-up the ImageCast Evolution. The programmed Memory Cards will have been inserted into the units in advance by the elections department with all security seals in place prior to shipment to the polling place. 6/18/2024 190 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.2.1 ICE Equipment Setup 6.2.1.1 Opening the Monitor ® 1. To get the ImageCast Evolution into the operating position, lift the monitor up and towards the front of the unit. Figure 6-1: LCD Monitor in Operating Position 2. At the back of the monitor lower the screen angle support stand. Fix the screen angle support stand into the desirable position. 3. Open up the privacy flaps to reveal the screen - first lift the top flap upwards and then open the side-flaps resting the top flap on top of them. 6.2.1.2 Election Memory Cards Two memory cards with election files are necessary to operate the unit. There are two slots for election file memory cards on the unit: The Primary card slot and the Backup card slot. Both are located underneath the first and second door on the right side of the ICE unit. 6.2.1.3 Attaching the Audio Tactile Interface 1. The A.T.I. device needs to be plugged in before powering up the unit. Open and lift up the fourth (4th) door on the right side of the ICE to expose the A.T.I. port. 2. Plug in the A.T.I. cable into the A.T.I. port. 3. Connect the headphones to the headphone jack on the bottom right of the ATI. Connecting the Paddles and Sip/Puff 1. Both the Sip/Puff or Paddles can be connected to the ATI via the 3.5 mm Sip/Puff jack located on the unit. 6/18/2024 191 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.2.1.4 Setting up the Voting Booth ® When the ImageCast Evolution is placed in working position, the monitor is up and towards the front of the unit. At the back of the monitor, the support stand is lowered into desirable angle position. The privacy flaps are opened up to reveal the screen. The top flap is lifted first and upwards while the side-flaps resting the top flap on top of them. 6/18/2024 192 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.2.2 ICP2 Equipment Setup The following sections discuss setting up the ICP2 and makes the following assumptions: • Tabulator is unpacked • Applicable SD memory cards are accessible 6.2.2.1 Setting up the Tabulator on the Ballot Box To set up the tabulator on its ballot box, perform the following: 1. Assemble the ballot box delivered to your polling location. 2. In the presence of Election Officials, verify that there are no ballots or other materials present in the ballot box. NOTE: Be sure to check all three sections of the ballot box: • Main compartment • Secondary compartment • Auxiliary compartment NOTE: It is recommended that the ballot box be secured after verifying it contains no ballots. 3. Place the tabulator and the ballot box in the polling room close to a power outlet, and where voters will have easy access to the tabulator. 4. Position the tabulator on top of the ballot box by placing it on the platform as shown in the figure below. Figure 6-2: Position the tabulator on top of the ballot box 5. Connect the round end of the AC to DC power adapter into the power port 6/18/2024 193 Version: 5.19::4 Chapter 6 - Polling Place Procedures located at the rear of the tabulator. Figure 6-3: Connect the round end of the AC to DC power adapter Route the power adapter cord to the side of the ballot box, as shown in Figure6-4. Figure 6-4: Route the power adapter cord to the side 6/18/2024 194 Version: 5.19::4 Chapter 6 - Polling Place Procedures Ensure the power cords do not present a tripping hazard to voters. Tape the power cords down to the floor and to the ballot box, if necessary. NOTE: Do not plug the tabulator's power cord into the DC power outlet. The thermal printer paper roll can now be replaced, if needed. 6.2.2.2 Replacing the Thermal Printer Paper Roll When the existing paper roll in the unit is running out, the paper display pink colored markings to warn officials that the roll is nearing completion. To remove the existing roll and replace it with a new one, perform the following: 1. Press in on the printer cover door release tab. 2. Lift the printer cover door. 3. Remove the plater pressure roller from the roller holders by pulling up it on. 4. Remove the used printer paper roll from the roll holder. 5. Insert into the roll holder a new printer paper roll. 6. Ensure the roll is feeding from the bottom and towards you. 7. Pull the paper towards you so that it passes over the plater pressure roller baseplate. 8. With the paper beneath it, push the plater pressure roller back into position above the roller holders. 9. Ensure the end of the plater pressure roller with the white cog is to the left. The plater pressure roller snaps into place. 10. Lower the printer cover door while inserting the end of the printer paper roll through the printer cover door opening. 11. Close the printer cover door. 12. Tear off the surplus paper. The tabulator can now be powered up. 6.2.2.3 Powering Up the Tabulator To power up the tabulator: 1. Ensure the tabulator is positioned on top of the ballot box with one end of the power adapter connected to the power port on the back of the unit. 2. Insert the plug of the power adapter cord into the DC outlet (or extension power cord attached to the outlet). 3. Ensure the cord does not present a tripping hazard. 4. Press in on the Administrator port door tab and lower the door. 6/18/2024 195 Version: 5.19::4 Chapter 6 - Polling Place Procedures 5. To the left of the Administrator SD memory card slot, set the power switch to on (downward position). The red power light turns on. 6. Using a pen or stylus, press in the reset button located to the left of the three LED lights next to the Administrator port door, and hold for 2 - 3 seconds. The tabulator emits a single long beep. The message "Verifying Configuration Files" appears on the LCD screen. After the files are verified, the Ready screen appears. Figure 6-5: Ready screen The security seals can now be applied. 6.2.2.4 Applying Security Seals Physical controls incorporate tamper evident seals that limit and detect unauthorized access to the ImageCast Precinct 2 tabulator. Election officials are free to use any tamper evident label or tamper evident tie wrap supplier. There are three (3) locations on the ImageCast Precinct 2 tabulator where security seals may be placed: • Memory card access ports (see 6.2.2.5 “Sealing Memory Card Access Ports”). • Thermal report printer door (see 6.2.2.6 “Sealing the Thermal Report Printer Door”). • Modem port (see 6.2.2.7 “Sealing the Modem Port”). Follow instructions provided by the Election Office for handling security seals. For securing the ballot box, apply tamper seals between the ballot box and tabulator. 6/18/2024 196 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.2.2.5 Sealing Memory Card Access Ports Place a lock, tamper evident label, or tamper evident tie wrap on the Administrator and Poll Work doors' lock loop as seen in the figure below. The doors remain locked during the entire deployment and through Election Day and night. The seals are broken only by administrators. Figure 6-6: Sealing Administrator and Poll Worker Memory Card Access Ports 6.2.2.6 Sealing the Thermal Report Printer Door Apply a seal to the thermal printer compartment as seen in the figure below. This protects against unauthorized access to this compartment. Figure 6-7: Sealing the Thermal Report Printer Door 6/18/2024 197 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.2.2.7 Sealing the Modem Port Apply a seal to the access cover protecting the modem port as seen in the figure below. This protects against unauthorized access to modem components. The access cover remains sealed during deployment and during Election Day. Only poll workers are authorized to break this seal prior to transmit election results. Figure 6-8: Sealing the Modem Port The poll can now be opened. 6.2.2.8 Ballot Review To review a ballot with voting issues detected during ballot scanning: The Ballot Review screen appears upon detection of issues. The screen displays all contents on the scanned ballots along with issues and corresponding issue descriptions. Figure 6-9: Ballot Review screen 6/18/2024 198 Version: 5.19::4 Chapter 6 - Polling Place Procedures 7. Tap the up and down arrows to review the issues with the voter. Figure 6-10: Ballot Review screen 8. When all issues have been reviewed with the voter, tap the green check mark. The Review Complete screen appears. Figure 6-11: Review Complete screen 9. Determine how the voter wants to proceed: • If the voter wants to cast the ballot as-is, at the tabulator, press CAST. • If the voter wants to make changes to the ballot before it is cast, at the tabulator, press RETURN. 6/18/2024 199 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.2.3 ICX Equipment Setup 6.2.3.1 Unpacking the Equipment The following steps are to be performed by an Election Official: ® 1. Remove the ImageCast X devices from their transport cases. 2. Remove the printers from their transport cases. ® 3. Unpack the following ImageCast X Peripherals: • Headphones (for ADA) • Audio Tactile Interface (ATI device) • The smart card(s) 6.2.3.2 Setting up the Equipment The following steps are to be performed by an Election Official: 1. Set up the booth according to the site layout map in the Supervisors Notebook. ® 2. Plug both the printer and the ImageCast X device into the UPS. 3. Plug the headphones into the headphone jack. 4. Plug the USB printer cable into printer and into a free USB port. 5. If the ICX device is to be used to support ADA voters then the appropriate ADA device should be plugged into a free USB port. 6/18/2024 200 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.2.3.3 Voting Booth Set Up When the ICX is placed in working position, to enable voter’s privacy, the voting booth should be positioned behind the ICX with the open side of the privacy surround facing a wall without a window and the area between the wall and the open side of the privacy surround are vacant while the voter is using this accessible voting station. The immediate surface area must be available for the voter’s unobstructed use of the accessibility device (i.e., ATI, Sip-and-Puff, or paddles). The assistive device must be positioned within the front half of the designated accessible voting area, on a horizontal surface with buttons facing up. The cables for accessible devices can be routed through a cable access hole or space at the rear area of the designated accessible voting booth. The accessible voting station should provide a clear floor space of 30 inches (760 mm) minimum by 48 inches (1220 mm) minimum for a stationary mobility aid. The clear floor space shall be level with no slope exceeding 1:48 and positioned for a forward or a parallel approach. 6.3 Opening the Polls 6.3.1 Opening the Polls on the ICX Election files must be present on the device prior to opening the poll. For more details on how to load election files onto the device, see section ® 4.5.2.4“ImageCast X Logic and Accuracy Test Procedures”. Prior to powering on the ICX, apply the security seals. NOTE: A seal is guided through each of the hasps in order to fasten the doors. NOTE: Adhesive-back seals need to be added to all doors on the backs of ® ImageCast X devices. 6/18/2024 201 Version: 5.19::4 Chapter 6 - Polling Place Procedures ® The ImageCast X Classic device has 2 doors on the back side of the enclosure, and the Plastic pull-up/pull tight seals are also used to fasten them. Figure6-14 and Figure6-15 show how the plastic seals should look when used on ® the ImageCast X Classic device. Figure6-12 and Figure6-13 show what an adhesive seal that's been tampered with looks like. Figure 6-12: Evidence of Tampering: Peeled Label Figure 6-13: Evidence of Tampering: Peeled and Reapplied 6/18/2024 202 Version: 5.19::4 Chapter 6 - Polling Place Procedures Figure 6-14: Top aValue security latch seal Figure 6-15: Bottom aValue security latch seal Now that the security seals are applied, the ICX can be powered on. 1. Power on the ICX by completing the following: • Open the security door. 6/18/2024 203 Version: 5.19::4 Chapter 6 - Polling Place Procedures • Press and hold the power button on the right of the unit until it lights up, then release the button. • Close the bottom security door. • Secure the bottom security door using a security seal. 2. Power on the printer by pressing the ON button. 3. Wait for the ICX device to finish booting. ® 4. Log into the ImageCast X application using the poll worker Smart Card. 5. Make sure the date and time are correct. 6. In the drop-down menu select a tabulator from the provided list. When clicking on the drop-down Tabulators menu, a keyboard pops up to type in the desired tabulator. The application starts verifying the election files, and when that's finished a dialog displays with information of the integrity of the election files. NOTE: If the list of tabulator is empty, that means that the poll worker's smart card is not programmed for the election database loaded on the ICX. A warning message may displays: “Loading tabulator failed. Election data contains tabulator with HASH different from one on smart card data”. 7. In the Info dialog, press OK. The Tabulator is now selected. 8. Press Open Poll. An Info dialog displays, with two options. 9. Press Yes. The poll is now open. 10. The device is ready for marking ballots. 6.3.2 Opening the Polls on the ICE In general, the precinct board or poll workers would perform the following items when opening the polling place: 1. Assemble voting booths, and in each booth display a copy of materials required by the California Elections Code. 2. Provide a pad of demonstration ballots, markers, and have suitable demonstration materials available. Dominion Voting Systems' plastic ballot box provides 8 hasp-type seal points for security seals. Figure6-16 and Figure6-17 depict where and how to apply security ties to the plastic ballot box. 6/18/2024 204 Version: 5.19::4 Chapter 6 - Polling Place Procedures 1. Break the seals on the Ballot Box in order to remove the ballot box lid and ® access the ImageCast Evolution. Figure 6-16: Green Ballot Box Seals ® 2. Position the ballot box, with the ImageCast Evolution sitting on top, so that an AC Main socket outlet is available to the unit. An extension cord can be used if needed. 3. Verify that all security seals are intact on the required locations. 4. Remove the three seals from the power cord compartment. The poll worker should inspect each of the ballot compartments main, secondary and auxiliary to ensure that there are no ballots present. Each compartment should then be sealed with one of the yellow padlock seals, and the seal 6/18/2024 205 Version: 5.19::4 Chapter 6 - Polling Place Procedures number recorded. ® Figure 6-17: ImageCast Evolution Seals 5. Plug the unit into the available AC Mains socket outlet. ® Figure 6-18: ImageCast Evolution Power Source 6. Power up the unit by lifting up the monitor to its operating position, as shown in Figure6-19. You can adjust the angle of the screen if needed and 6/18/2024 206 Version: 5.19::4 Chapter 6 - Polling Place Procedures open up the privacy flaps to reveal the touchscreen. ® Figure 6-19: Lifting the LCD Screen on the ImageCast Evolution ® 7. Once the ImageCast Evolution has powered up, the system will prompt for the iButton Security Key to be applied to the iButton Security Key receptacle. Figure 6-20: iButton Security Key Prompt 8. Press the iButton Security Key firmly to the receptacle, and hold it in place until the login screen appears on the touchscreen. 9. On the Authorization screen, enter the username and password specific for 6/18/2024 207 Version: 5.19::4 Chapter 6 - Polling Place Procedures the project and press OK. In the event that the username and password are incorrect, the screen will clear the text and provide a new opportunity to enter the correct username and password. 10. Once logged in, the Poll Worker menu will appear. 11. Press Open Poll to open the Poll Management screen, see Figure6-21. You will be presented with the following three options: a. Poll Status b. Print Zero Tape 6/18/2024 208 Version: 5.19::4 Chapter 6 - Polling Place Procedures c. Number of Copies to Print Figure 6-21: Main Menu 12. To change the number of Zero Tapes to be printed, press Change beside the 'Number of Copies to Print' option. See Figure6-22. 13. You will be prompted to enter the number of Zero Tapes you wish to print. Enter the desired number. Figure 6-22: Number of Zero Tape Copies to Print 6/18/2024 209 Version: 5.19::4 Chapter 6 - Polling Place Procedures 14. Press OK to return to the Poll Management screen. 15. Press the Open button beside the Poll Status option. Figure 6-23: Open button in the Main Menu 16. A confirmation screen will appear Press OK to continue. 17. If the Zero Tape setting was set to “Print” the Zero Tape will begin printing and the Printing in progress screen will appear. Pressing the Cancel button will stop the printing of the tape. Figure 6-24: Printing of Zero Tapes in Progress 6/18/2024 210 Version: 5.19::4 Chapter 6 - Polling Place Procedures 18. Once the Zero Tape has been printed, the Printing completed screen will appear. To print more copies of the Zero Tape press Yes, otherwise press No. Figure 6-25: Printing of Zero Tape Completed 19. The Administrative Menu screen appears with the poll open and ready for operation. Figure 6-26: Poll Ready for Operation 6/18/2024 211 Version: 5.19::4 Chapter 6 - Polling Place Procedures 20. Place a sample ballot in a location that is visible to voters. Figure 6-27: Sample Ballot 6/18/2024 212 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.3.3 Opening the Polls on ICP2 When advised to do so, open the poll. To open the poll: 1. Contact the Security Key to the Security Key receptacle. 2. While maintaining contact, the Please Enter Password screen appears. Figure 6-28: Enter password 3. Remove the iButton Security Key from its receptacle, enter the provided password, and then tap Enter. The message "Password Correct" appears and the election project is verified. Figure 6-29: Password correct 6/18/2024 213 Version: 5.19::4 Chapter 6 - Polling Place Procedures The Main Menu screen appears. Figure 6-30: Main Menu screen 4. From the Main Menu screen, tap Poll Management. The Poll Management screen appears. Figure 6-31: Poll Management screen 5. From the Poll Management screen, tap Open Polls. The Please Enter Password screen appears. 6. Enter your password and tap Enter. 6/18/2024 214 Version: 5.19::4 Chapter 6 - Polling Place Procedures The Open Poll Confirmation screen appears. Figure 6-32: Open Poll Confirmation screen 7. From the Open Poll Confirmation screen, tap Confirm. The message "Printing in progress" appears as the thermal report printer prints the zero report. Figure 6-33: Printing in Progress screen The Please Insert Ballot screen appears with status Poll Open displayed in the 6/18/2024 215 Version: 5.19::4 Chapter 6 - Polling Place Procedures top left-hand corner. Figure 6-34: Please Insert Ballot screen 8. Confirm the following zero report content: • Report header displays the correct: • Precinct • Voting Location name and/or Electoral District number • Serial number matches the tabulator's serial number, located on the right-hand side. • Total Scanned is zero and Total Voters is zero. NOTE: If any of this information is incorrect, contact your Election Office immediately. 9. Process the zero report as specified by your jurisdiction. 10. From the lower left-hand corner of the Please Insert Ballot screen, ensure the Ballot Counter field displays 00000. NOTE: If this field is incorrect, contact your Election Office immediately. 6.3.3.1 Viewing Tabulator Info on the LCD Screen In addition to tabulator information displayed on the zero report, information specific to the tabulator can be viewed on the Tabulator's LCD screen. To view the tabulator information: 1. At the Please Insert Ballot screen, press the iButton Security Key to the Security Key receptacle. 6/18/2024 216 Version: 5.19::4 Chapter 6 - Polling Place Procedures The Main Menu screen appears. Figure 6-35: Main Menu screen 2. From the Main Menu screen, tap Utilities. The Utilities screen appears. Figure 6-36: Utilities screen 3. From the Utilities screen, tap Tabulator Info. 6/18/2024 217 Version: 5.19::4 Chapter 6 - Polling Place Procedures The first Tabulator Info screen appears. Figure 6-37: Tabulator Info screen 4. Tap the white circle displayed at the bottom of the LCD screen. The second Tabulator Info screen appears. Figure 6-38: Tabulator Info screen 5. When done viewing the tabulator information, tap OK, then Back, and then Exit. The Please Insert Ballot screen appears. The tabulator is ready to scan ballots. 6/18/2024 218 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.4 Polling Place Procedures The following two sections give some general procedural information related to the polling place. In general, the precinct board will perform the following tasks at each polling location on Election Day: 1. At least every hour, inspect each booth to ensure there are no electioneering materials present, and that the booth/voting machine is otherwise suitable for voting. As far as possible, defacement conditions shall be corrected according to the jurisdiction's practices and in conformance with California Election code. 2. Offer to instruct each voter in the proper method of voting, including further instruction and practice time, if necessary, and as applicable. The poll worker would be responsible for the following type of assistance when the voter enters the polling place: NOTE: No poll worker, or any other person, may record the time at which, or the order in which, voters vote in the polling place. 1. Provide the voter with a ballot, secrecy envelope, and proper marking device to complete the ballot; be sure to include any instructions per jurisdiction or local statute, if required. To ensure a smooth election process: a. Checking each ballot before giving it to the voter to ensure there are no torn or faulty edges. Looking for abnormally light printing and improper registration of trim marks. The trim marks show the edges on which the ballot should be cut or trimmed. 2. If requested by the voter, use the demonstration ballot to show the voter: a. How to fill the oval adjacent to the voter's selected candidate name or proposition. ® b. The different ImageCast Evolution screen views. This may include explaining the meaning of various messages that may appear on the LCD screen and ensuring that the voter understands all aspects of the voting process. 3. After the voter has completed the ballot, instruct the voter to insert the ballot ® into the entry slot of the ImageCast Evolution tabulator unit, releasing the ballot after insertion. The ballot will be drawn automatically into the unit. 4. Ask the voter to remain at the unit until the ballot is fully processed and deposited into the ballot box. 5. The voter may wish to ensure that the ballot count has increased by one, indicating that the ballot has been accepted. NOTE: If the ballot is returned, the count will not increment. 6/18/2024 219 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6. If any of the second-chance voting scenarios occur (i.e. blank ballot, overvote, undervote), explain to the voter that the ballot has not yet been counted, and explain the reason for the warning message. Change Language: In locations where more than one language option is needed, the poll worker may need to assist the Voter with language selection. Activating Accessible Audio Ballots: In locations where accessible voting features ® of the ImageCast tabulator units are in use, the poll worker will need to activate accessible voting sessions and may need to assist the Voter through the audio process. Monitoring Voter and Machine Operation: The poll worker must monitor the ® operation of the ImageCast tabulator unit in order to ensure that everything is operating correctly. If there were any technical issues, the poll worker would follow procedures provided by the local jurisdiction. Assisting Voters that Require Physical Assistance: The poll worker may also need to assist voters that require physical assistance as per local statutes. 6.4.1 ImageCast® Evolution 6.4.1.1 Standard Voting Session To begin a voting session: 1. Press the Standard Voting button on the left side of the screen and then press Start. 2. Press OK on the confirmation message. Figure 6-39: Verification Messages 6/18/2024 220 Version: 5.19::4 Chapter 6 - Polling Place Procedures 3. After successful verification, a paper ballot needs to be inserted into the ballot entry slot. The system will wait a few seconds for the ballot. 4. In case verification fails, the system will inform you what has gone wrong. Figure 6-40: Time out for Inserting Ballot 5. You can review your marks. If you want to cast your ballot, press Cast. If not, press Return. In this case, the paper will be returned for your correction. Figure 6-41: Ballot Review 6/18/2024 221 Version: 5.19::4 Chapter 6 - Polling Place Procedures If you have selected to cast your ballot, a screen that asks you to confirm your action will appear, as shown in Figure6-42. Figure 6-42: Cast Ballot Confirmation In case of multi-card ballot, a screen that informs you that you can insert additional ballot cards will be displayed. 6/18/2024 222 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6. If you want to continue, press the Continue button. To finish the session, press Cancel. Figure 6-43: Multi-card Session Continuation You will be notified that the session is complete. A new welcome screen will then be displayed, and a new voting session can begin. Figure 6-44: Session is Complete 6/18/2024 223 Version: 5.19::4 Chapter 6 - Polling Place Procedures In case a used ballot is inserted, an error message will inform you that the inserted ballot has already been used and that it cannot be inserted again. Figure 6-45: Ballot Already Inserted 6.4.1.2 Write-In (Ballot Review Disabled) If the Ballot Review is “Disabled”, the correctly marked ballot will automatically be cast and the ballot will be dropped into the main ballot box chamber. 6.4.1.3 Overvote (Ballot Review Enabled) Insert the ballot with an overvoted contest. Figure 6-46: Standard Voting - System Ready Screen 6/18/2024 224 Version: 5.19::4 Chapter 6 - Polling Place Procedures The screen will display a ballot review and mark the overvoted contest, as shown in Figure6-47. The ballot will remain in the scanner until the voter presses the Return button. There is no option to cast the ballot. NOTE: Jurisdictions can configure the MBS whether to accept overvoted ballots. If the configuration is such that accepts overvoted ballots, they could be cast but the voted would not count towards the result totals. Figure 6-47: Overvote Ballot Review Screen 6.4.1.4 Overvote (Ballot Review Disabled) Insert the ballot with an overvoted contest. The error screen will appear indicating which contests were overvoted. The ballot will immediately be returned back to the voter and will hang on the insert slot of the tabulator until the voter removes the ballot. Figure 6-48: Overvote Error Screen 6/18/2024 225 Version: 5.19::4 Chapter 6 - Polling Place Procedures If the voter presses the OK button the screen will change and instruct the voter to remove the ballot. Figure 6-49: Remove Ballot from the Device Screen 6.4.1.5 Undervotes Starting from the Standard Voting screen, insert the ballot with a blank/ undervoted contest. If the Ballot Review has been enabled, then the ballot review screen will appear indicating which contest has been undervoted. Depending on the configuration set in the MBS file, the ballot may, or may not be, cast. If the Return Ballot Immediately Option has been set, the screen shown in Figure6-50 appears. Figure 6-50: Undervote Ballot Review Screen. 6.4.1.6 Ambiguous Marks (Ballot Review Enabled) Starting from the Standard Voting screen, insert the ballot with an ambiguous mark. When an ambiguous mark is detected the ballot review screen appears and indicates which contest/s the ambiguous mark was detected. Depending on the MBS configuration, the ballot may or may not be allowed to be cast. The ballot review screen identifies the ambiguous mark on the specific choice where it 6/18/2024 226 Version: 5.19::4 Chapter 6 - Polling Place Procedures happened. The ballot is returned and hangs in the throat of the insert slot of the scanner. The voter can either pull the ballot out or select Return. Figure 6-51: Ambiguous Mark Ballot Review Screen. 6.4.1.7 Ambiguous Marks (Ballot Review Disabled) Starting from the Standard Voting screen insert the ballot with an ambiguous mark. The error screen will appear indicating where the ambiguous mark was detected. The ballot is immediately returned and hangs off from the insert slot of the scanner. The voter can either pull the ballot out, which will return them to the Standard Voting screen, or press the OK button, which will display a screen instructing the voter to pull the ballot out. Figure 6-52: Ambiguous Mark Error Screen. 6.4.1.8 Correctly Marked Ballot with No Write Ins Starting from the Standard Voting screen, insert the correctly marked ballot. The ballot review screen will appear showing the selected choices. The voter can Cast or Return the ballot. If the voter casts the ballot, the ballot is dropped into the 6/18/2024 227 Version: 5.19::4 Chapter 6 - Polling Place Procedures ballot box and the Ballot Counter located in the bottom-left of the screen increments up by one. Figure 6-53: Valid Ballot Review Screen. ® 6.4.1.9 Operating the ImageCast Evolution on Battery A battery power source is provided in the event that the main electric supply is disrupted. The battery power source operates the system and allows for the casting of votes for a period of two hours under normal operating conditions (100 voters per hour, and two AVS voters per hour). The system will shut down and preserve the integrity of votes cast prior to the power failure, and resumes functionality when power is provided or restored without significant or intrusive power-up procedures. In the event of a power failure, the equipment will continue to operate and indicate the battery life on the LCD monitor and side panel LED lights. The switch from battery power to AC power (or vice versa) takes place automatically. If the AC power is disconnected or unavailable, the unit will continue to operate on battery power as long as a sufficient charge remains in the ® battery. When AC power is reconnected or otherwise resumes, the ImageCast Evolution automatically returns to AC power mode. 6.4.1.10 Changing the Printer Paper Tape Thermal Paper Removal Lift the thermal printer door upward to access the printer module. On the left side of the thermal printer module, press the green release lever into an angled position. 6/18/2024 228 Version: 5.19::4 Chapter 6 - Polling Place Procedures This releases the thermal head from the platen roller to allow the paper to be removed or fed in smoothly. Figure 6-54: Lever in Head Up/Down Position Remove the old partial paper roll (if any) out from the printer compartment. Slide the roll shaft out of the paper roll. 6.4.1.11 Thermal Paper Installation Thermal Paper installation can be performed even while the system is powered on although it is recommended that the user read the tabulator handling notes prior to performing any maintenance routine on the machine. 1. Remove the end-holding tape from a new paper roll to free the roll end. Unwind the paper roll past any glue residue from the tape. 2. Cut the edge of a new paper roll relatively straight. 3. Feed the roll shaft through the new paper roll. 4. Place the new roll into position on the paper roll tray such that the paper unreels from underneath the roll and upwards. NOTE: Thermal Paper is chemically coated usually only on a single side of the roll. Heat from the thermal printer will therefore print only on that side of the paper. A fingernail swiped quickly across either side of the paper can generate enough heat from friction to produce a mark and thus identify the coated side of the paper roll. This is the side that needs to be placed against the thermal printer head. 6/18/2024 229 Version: 5.19::4 Chapter 6 - Polling Place Procedures 5. Feed the straight-cut edge of paper underneath the platen roller. As the paper is fed through, it will find its way between the platen roller and thermal head. Figure 6-55: Paper Roll Installed 6. Pull the paper up then press the green release lever into the horizontal head down position to secure the paper in place. 7. Pull the paper one more time and ensure alignment to the platen roller. 8. Close the printer door making sure the thermal paper feeds through it. 6.4.2 Standard Voting Session On ICP2 Upon entering the voting place, a voter is handed a ballot and performs the following: 1. In the voting booth, the voter marks a paper ballot with the provided pen. 2. Voter insert the ballot into a secrecy folder. 3. Once the ballot is concealed, the voter leaves the voting booth and approaches the tabulator. 6/18/2024 230 Version: 5.19::4 Chapter 6 - Polling Place Procedures At the tabulator: 1. The ballot is fed into the ballot input slot located on the front of the tabulator, ensuring that the ballot is inserted face-down to protect the confidentiality of the vote. 2. The poll worker instructs the voter to wait for the ballot to be successfully cast. 3. The voter should leave the secrecy folder with the poll worker. The tabulator pulls the ballot from the secrecy folder and scans the content. The message "Scanning Ballot, please wait" appears. Figure 6-56: Scanning Ballot screen If no issues are found with the ballot, the message "Ballot Successfully Cast" appears and the ballot is tabulated. 6/18/2024 231 Version: 5.19::4 Chapter 6 - Polling Place Procedures Figure 6-57: Ballot Successfully Cast screen The ballot exits the tabulator from the rear exit slot and drops into the ballot box. The voter is free to leave the voting place. NOTE: When inserting marked ballots into the ballot entry slot, non-typical scenarios may arise. These depend on how the voter marked their ballot, and how the tabulator is configured (MBS) to respond. It is very important that the voter remain at the tabulator while the ballot is cast, so that if a nontypical scenario occurs, they have the opportunity to respond. If the tabulator detects certain non-typical voting scenarios a warning message may be displayed on the screen giving the option to the voter to cast the ballot as-is or return the ballot for correction. NOTE: Standard Ballot Review must be set to Enabled for non-typical voting scenario warning messages to be displayed. Non-typical voting scenarios include: • One or more undervoted contest(s) • One or more overvoted contest(s) • Combination of undervoted and overvoted contests • Blank ballot • Misread ballot • Invalid ballot 6/18/2024 232 Version: 5.19::4 Chapter 6 - Polling Place Procedures • Ambiguous marks • Missing election official signature Please refer to Handling Non-typical Voting Scenarios for details on how to handle these various voting scenario 6.4.2.1 Handling Non-typical Voting Scenarios Upon inserting ballots into the ICP2's ballot entry slot, there are a few scenarios that may arise. These various ballot scenarios depend on the manner in which the voter has marked the ballot, as well as the configuration of the tabulator. The tabulators Machine Behavior Settings (MBS) are configured prior to the election to detect for particular ballot scenarios and elicit various responses based on the type of ballot scenario detected. Voting scenarios can include the following: • One or more undervoted contest(s) • One or more overvoted contest(s) • Combination of undervoted and overvoted contests • Blank ballot • Ambiguous marks detected • Invalid or defective ballot The following are four possible tabulator responses for each scenario; the tabulator's MBS determines which one is applied. • Automatically accept ballot • Automatically reverse ballot • Prompt voter • Prompt Voter with a confirmation The user cases for all the voting scenarios are similar, and dependent on the MBS options above. The following will show the use cases for each of the above MBS options for overvoted, undervoted, and/or blank ballots. The use cases for defective ballots, invalid ballots, and ambiguous marks can be found in Second Chance Voting Scenarios. 6.4.2.2 Second Chance Voting Scenarios The following scenarios discuss possible non-typical voting issues and how they are to be handled. 6/18/2024 233 Version: 5.19::4 Chapter 6 - Polling Place Procedures Blank Ballots A blank ballot is a ballot that contain no voting position marks readable by the tabulator. It may be truly blank in all voting positions, or it may have marks in these positions which the tabulator cannot read because they are of insufficient density. The tabulator will prompt a Return to Voter message. 1. In the most common configuration, the ICP2 will display a warning message on the LCD screen explaining that a blank ballot has been detected. 2. As part of the Return to Voter message, the voter is given the option to cast the ballot as-is by pressing the Cast button or to return the ballot for correction by pressing the Return button. 3. According to the jurisdictional procedures in place, the following actions are also available: • Try Ballot Again: If a voter does not mark their ballot properly by filling in the voting position, the ballot is returned to the voter. In this case the ballot can be pulled out and the voter is instructed on the proper manner of marking candidate votes and can even use the same ballot. • Issue New Ballot: If a voter fills in the voting position but uses a non- standard marking device, the unit may not be able to read the vote marks. In this case, the voter should be issued a new ballot. The problem ballot is placed in a spoiled ballot envelope. 6/18/2024 234 Version: 5.19::4 Chapter 6 - Polling Place Procedures • Auxiliary Bin: Pull the ballot out of the ballot slot and place it in the auxiliary bin for review after closing the polls. 6.4.2.3 Overvoted Ballots A ballot is overvoted when the voter has voted for more than the allotted number of candidates for the office being contested. If the voter has made detectable marks in more voting spaces than the maximum allowed for a given contest, this is called an overvote. The tabulator will prompt a Return to Voter message. • In the most common configuration, the ICP2 displays a message is the Ballot Review screen indicating overvated contest. • In the Review Complete screen, the voter is given the option to cast the ballot as-is by pressing Cast or to return the ballot for correction by pressing Return. • According to the jurisdictional procedures, the following actions are also available: • Issue New Ballot: If the option is to pull the ballot out, the voter can be issued a new ballot and instructed on the proper number of votes allowed per office. Note that the title of the overvoted office is printed as part of this Return to Voter message in order to allow the Poll worker to specifically instruct the Voter in regard to the number of votes allowed for that specific office. The problem ballot is placed in a spoiled ballot envelope. • Use Auxiliary Bin: Pull the ballot out of the ballot slot, and place it in the auxiliary bin for review after closing the polls. 6/18/2024 235 Version: 5.19::4 Chapter 6 - Polling Place Procedures Undervoted Ballots A ballot is undervoted when the Voter has voted for less than the total number of election contests listed on the ballot, or less than the number of positions to be filled for a single office. If the voter has made detectable marks in fewer voting spaces than the maximum allowable for a given contest, this is called an undervote. The ImageCast Precinct 2 tabulator can be configured to behave in any of four different ways when this occurs: • Tabulator forwards the ballot into the ballot box with no voter interaction message • Tabulator displays a message is the Ballot Review screen indicating the undervoted contest(s). • In the Review Complete screen, the voter is given the option to cast the ballot as-is by pressing Cast or to return the ballot for correction by pressing Return. • If the voter presses Cast, the ballot is accepted and placed in the ballot box, and all valid votes are recorded. If the voter presses Return, the ballot is returned to the voter for correction. Write-in Ballots A Write-in ballot is a ballot where a vote has been cast in a race for a candidate whose name does not appear on the ballot. Ballots containing write-in selections are diverted into the secondary compartment of the ballot box for future adjudication by the appropriate election officials, after closing the polls. Damaged/Error Ballots (Misread Ballots) A misread warning indicates that the ICP2 has not recognized all of the features on the ballot or that certain essential ballot identification markings cannot be found. This usually occurs if the ballot is physically damaged (i.e. torn or folded) or there are stray markings that were inadvertently made on the ballot. These markings may obstruct certain important identifiers along the sides or the bottom of the ballot. The tabulator is usually configured to automatically return the ballot, and display a Misread warning message on the LCD screen. Explain to the voter that the ballot was not counted by the tabulator and needs to be re-inserted. Re-insert the ballot into the tabulator. If the ballot is repeatedly rejected, instruct the voter to obtain and mark a new ballot. Make sure that the voter understands how to properly mark the ballot. 6/18/2024 236 Version: 5.19::4 Chapter 6 - Polling Place Procedures Misread errors can also be caused by: • Smudged ink within the paper path, if an incorrect pen was used and the ink did not dry on the ballot before insertion into the tabulator; • Dirt/dust build-up over time within the Tabulator Paper Path system (this is unlikely). The election jurisdiction has tested the voting unit with samples of the actual ballots. However, either ballot printing or ballot trimming problems could have occurred with the batch of ballots in the Precinct 2 which could cause ballots to be returned to Voter with error messages. In addition, while the ICP2 is a very robust industrial strength unit, the possibility always exists for an electro-mechanical failure to occur which would cause false ballot error messages to occur. The following choices are available: • Try Ballot again: If the ballot is not visibly damaged, insert the ballot in a different orientation to see if the error repeats itself. • Issue New Ballot: If the ballot is physically damaged, pull the ballot out of the unit, the Voter can be issued a new ballot and instructed on the proper number of votes allowed per office. The problem ballot is placed in a spoiled ballot envelope • Use Auxiliary Bin: If there are persistent misreads, pull the ballot out of the Ballot Slot, and place it in the Auxiliary Bin for review after closing the polls. Contact Election Technical support. Invalid Ballots (Un-processable Ballots) An Invalid Ballot is one that the tabulator identifies as an official ballot, but it was not configured to accept (e.g. a ballot that was meant for another district, delivered in error). The tabulator is usually configured to automatically return the ballot, displaying an Invalid Ballot warning message on the LCD screen for five seconds, and emitting an audible beeping sound. After this time, the screen will return to System Ready mode. An unprocessable ballot cannot be processed because of an invalid Security ID header code, etc. The unprocessable ballot is returned to the voter. The following choices are available: • Try Ballot Again: The ballot may be tried again. • Issue New Ballot: A new ballot may be issued to the voter. The problem ballot is placed in a spoiled ballot envelope. • Use Auxiliary Bin: Pull the ballot out of the ballot slot, and place it in the auxiliary bin for review after closing the polls. 6/18/2024 237 Version: 5.19::4 Chapter 6 - Polling Place Procedures Ambiguous Marks The ICP2 assesses voter intent based on the number of pixels detected in each voting box. The thresholds used when making this determination are configured prior to the election. If the tabulator detects a voter mark that is not large enough or dark enough to clearly show the voters intent, the tabulator is configured to automatically return the ballot, displaying the Ambiguous Marks warning. Explain to the voter that the ballot was not counted by the tabulator. The poll worker can try changing the orientation of the ballot and re-feeding it into the tabulator to see if it is accepted. This should be repeated up to three times. If the ballot is still not accepted by the tabulator after 3 attempts and the warning message continues to be Ambiguous Marks, the poll worker should ask the voter to review the ballot, to ensure that it is clearly marked in the voting areas provided, and that there are no stray marks. If needed, instruct the voter to return to the voting booth to re-mark their ballot, ensuring that they completely fill in the voting target. Confirm that the voter understands how to mark the ballot. Use the following procedure: 1. User feeds ballot into the unit, and the ballot is imaged and interpreted. The following message appears on the LCD operator interface: “Warning! One or more ambiguous marks detected on the ballot”. Please correct all ambiguous marks and refeed the ballot. 2. The machine will automatically return the ballot. 3. Explain to the voter that the ballot cannot be processed because one or more ambiguous marks were detected and the machine cannot be certain of the voters intent. 4. Ask the voter to review the ballot to ensure that it is clearly marked in the spaces provided and that there are no stray marks. 5. Allow the voter to return to the voting booth, and make sure the voter understands how to mark a ballot. 6. If the machine continues to reject the ballot, have the voter return the ballot and obtain a new one. 6.4.2.4 RCV Voting Scenarios The following sections describe RCV (Rank Choice Voting) scenarios and how they are handled by the ICP2 tabulator. Duplicated Candidate A consecutive sequence of rankings for the same candidate. 6/18/2024 238 Version: 5.19::4 Chapter 6 - Polling Place Procedures The tabulator is configured to: • Prompt the voter with a detailed warning description and Cast/Return option and not ask for a confirmation when the ballot is cast. Inconsistent Ordering A candidate is ranked both above and below another candidate. The tabulator is configured to: • Prompt the voter with a detailed warning description and Cast/Return option and not ask for a confirmation when the ballot is cast. Skipped Ranking A higher ranked choice is missing while a lower ranked choice has been made. The tabulator is configured to: • Automatically cast the ballot Overvoted Ranking A ranking exists that has more than one candidate marked. The tabulator is configured to: • Prompt the voter with a detailed warning description and Cast/Return option and not ask for a confirmation when the ballot is cast. Unvoted Contest No candidates were ranked. The tabulator is configured to: • Automatically cast the ballot Unused Ranking Additional rankings at the end are left empty by the voter. The tabulator is configured to: • Automatically cast the ballot The following scenarios apply when the Major Office option is selected in EED. ® For more information, please refer to Democracy Suite EMS Election Event Designer User Guide, Section Defining Office. Major Duplicated Candidate A consecutive sequence of rankings for the same candidate. 6/18/2024 239 Version: 5.19::4 Chapter 6 - Polling Place Procedures The tabulator is configured to: • Prompt the voter with a detailed warning description and Cast/Return option and not ask for a confirmation when the ballot is cast. Major Inconsistent Ordering A candidate is ranked both above and below another candidate. The tabulator is configured to: • Prompt the voter with a detailed warning description and Cast/Return option and not ask for a confirmation when the ballot is cast. Major Skipped Ranking A higher ranked choice is missing while a lower ranked choice has been made. The tabulator is configured to: • Automatically cast the ballot Major Overvoted Ranking A ranking exists that has more than one candidate marked. The tabulator is configured to: • Prompt the voter with a detailed warning description and Cast/Return option and not ask for a confirmation when the ballot is cast. Major Unvoted Contest No candidates were ranked. The tabulator is configured to: • Automatically cast the ballot Major Unused Ranking Additional rankings at the end are left empty by the voter. The tabulator is configured to: • Automatically cast the ballot 6.4.3 Standard Voting on ICX The Voting Session is activated by inserting ICVA programmed Voter Activation Card into the Smart Card Reader. NOTE: If the voter card is removed before the voting session is complete, the voting session is terminated and selections are not stored. 6/18/2024 240 Version: 5.19::4 Chapter 6 - Polling Place Procedures Upon inserting a card, the voter is asked to select the language that they prefer to perform the voting session in. Once the voting language is selected, the voter is presented with the voting interface. 6.4.3.1 Voting Interface During the active voting session, there are several menus and bars intended for adjusting the voting interface as desired and navigating through the ballot. At the top of the screen, an Action bar is placed containing buttons for changing various graphic and audio settings. These settings can be changed at any point in the voting session and are consistent throughout the whole session. Figure 6-58: Action Bar • The Language button opens a pop-up menu with all the languages defined for current elections. The voter can change the language by pressing a checkbox with the desired language. • Text size can be changed by choosing one of the options displayed by pressing a Text Size button. • The Audio button is active only in an AVS session. For details refer to AVS (Accessible Voting Session) Voting Interface section in the Democracy ® ® Suite ImageCast X User Guide. • The View button allows changing the visual theme of the voting interface. • The More button allows the voter to cancel the current voting session by tapping the Cancel Activation in the pop-up menu, or display the information about the ICX device and software by pressing the About button. Figure 6-59: Contest Stripe The Contest Stripe is located right under the Action bar and is used for navigation between the contests on the ballot. By tapping on the desired button, the corresponding contest will be displayed on the screen. 6/18/2024 241 Version: 5.19::4 Chapter 6 - Polling Place Procedures Figure 6-60: Stripe The Stripe is located right under the Contest Stripe and is used to indicate the page number the voter is on during an active voting session as well as the voter’s chosen party. Both options can be enabled or disabled through the Edit Configuration option in the Technician Menu, or through the MCF in EED during project creation. NOTE: The following applies depending on the type of election: For open primary elections the party name shown is the selected party name. It is already present on the screen per design for open primary elections. Setting Show party name to true will duplicate this information on the screen. For closed primary elections the party name is not present per design, so it's only visible if configured. For general elections, the party name is not present on the screen ignoring the configuration. Figure 6-61: Navigation Bar Beside the Contest Stripe, the voter can navigate between the contests by using the Navigation bar at the bottom of the screen. Pressing the Previous and Next buttons will display the previous/next contest listed in the Contest Stripe. Selecting the Review button will advance the voter to the Review screen that contains all contests and choices marked by the voter. The Review screen will also display notifications about any errors or warnings if the ballot is not valid or incomplete. The voter can navigate through all of their choices by pressing More at the bottom/top of the contest list. In case the voter wants to change the choices for a specific contest, selecting (tapping) that contest in the review list will return the voter to that specific contest screen. The same functionality is provided by pressing the Back to Ballot button in the bottom left corner of the Review screen. 6/18/2024 242 Version: 5.19::4 Chapter 6 - Polling Place Procedures The ballot is printed by selecting the Print Ballot button located in the right bottom corner of the screen. Pressing this button prompts a final dialog that, again, displays any warnings specific to the ballot and provides the options to confirm the ballot printing or to return to the Review screen. The Marked ballot is printed by selecting the Print your ballot button in the dialog. After the voting session is complete, a screen is presented informing the voter of the result of the action. At this point, the voter can safely remove the Smart Card. ® 6.4.3.2 ImageCast X Early Voting ® Since ImageCast X is a Ballot Marking Device, the procedure is the same as for ® ImageCast X Election Day procedure. ® 6.4.3.3 ImageCast X Manual Session Activation To start a manual session: 1. Insert the Poll Worker smart card and enter the PIN. The log-in page displays. 2. Click the Activate Ballot tab. The Activate Ballot window displays. 3. With the on-screen keyboard, type in the Ballot Activation Code. You can also Enable AVS Controller on this window. 4. Click NEXT. 5. Click Continue. The voting session is now open. 6.5 Accessible Voting Procedures 6.5.1 Accessible Voting on ICE 6.5.1.1 Accessible Voting Session NOTE: If the AVS voting session consists of a multi-card ballot, a poll worker is required to manually reactivate the AVS session after each card of the multi-card ballot is scanned. Audio Only Voting using the Audio Tactile Interface If the voter decides to turn the display off during their voting session, and commence an audio session only, the voter must press the blue down arrow when presented with the option to do so. Audio instructions explain to the voter how ® they will navigate and make selections to their ballot. The ImageCast Evolution's LCD screen will read “An audio voting session is in progress”. The ATI will operate in the same manner as it does in the Audio and Visual voting session. 6/18/2024 243 Version: 5.19::4 Chapter 6 - Polling Place Procedures Accessible Voting Session To start an Accessibility Voting Session: 1. Apply the iButton Security Key to the receptacle to access the Poll Worker Main Menu, see Figure6-62. 2. On the Poll Worker Menu screen, select the Accessible Voting option. Figure 6-62: Poll Worker Main Menu screen 3. Press the Start button next to the AV Session in the Poll Management - Accessible Voting Session screen. Figure6-63 shows the options that are set for Ballot Review. By pressing the Change option, additional ballot review options will appear. 4. On the Start AV Session Confirmation screen, press OK to continue with AV session (in the activity status bar, Option will clearly indicate which option has been set). Note: Depending on the MBS settings, the Authorization screen can vary. It could be set to prompt for the user name and password or password only. In addition, the MBS can be configured not to prompt for credentials upon 6/18/2024 244 Version: 5.19::4 Chapter 6 - Polling Place Procedures starting the AV session. In case when the user is asked for credentials, they needs to enter the correct credentials and on the confirmation screen, press OK to continue. Figure 6-63: Poll Management - Accessible Voting Session ® ImageCast Evolution will perform variety of verification steps. Next, the Accessible Voting screen (“System ready to initiate AV session Please insert a blank ballot”) is displayed, prompting the user to insert a blank ballot. Audio with the same instructions will be heard over the headphones. 5. Insert a blank ballot to initiate the session. 6/18/2024 245 Version: 5.19::4 Chapter 6 - Polling Place Procedures Figure 6-64: Welcome to Your Voting Session After the ballot has been successfully accepted, the language selection will appear. Selection may need to be done with the help of a poll worker. 6. Select the language, and then press the Confirm button. Figure 6-65: AVS - Language Selection 7. Help a voter to choose an accessible device. Select ATI option. 6/18/2024 246 Version: 5.19::4 Chapter 6 - Polling Place Procedures NOTE: From this moment, language, text size and color can be changed. These options are available in the menu located in top right corner of the screen. The Audio/Video option enables you to vote with audio without using an accessible device. The voter will have audio instructions available, however, a headset needs to be connected to the ATI device. Figure 6-66: AVS - Device Selection screen 6/18/2024 247 Version: 5.19::4 Chapter 6 - Polling Place Procedures From this point forward, a voter can vote independently, without any poll worker's assistance. The ATI Instructions screen displays a labeled diagram of the ATI indicating what action each button performs. All instructions are followed by audio. 8. To change language, text size, audio, or color options, press the blue up arrow on the ATI to navigate to the Settings menu. 9. To move between options within the settings menu, press the yellow left or right arrow buttons on the ATI. 10. To navigate to the OK, Got It! option to proceed, press the blue down arrow button on the ATI. 11. Once you have completed selecting settings, press the X-shaped select button. Figure 6-67: AVS - ATI Instructions screen 6/18/2024 248 Version: 5.19::4 Chapter 6 - Polling Place Procedures If the voter chooses to use paddles, the following screen will appear (see Figure6-68). Otherwise, please skip this screen and navigate to the AVS - Display On Selection screen. 12. To confirm a selection, press the left (L) red paddle. The voting screen displays. 13. From there, press the right (R) blue paddle to move and red left (L) paddle to confirm the selection. Figure 6-68: AVS - Paddles Instructions Screen If the voter chooses to use a Sip-and-Puff device, the following screen appears (see Figure6-69). If not, skip this screen and navigate to AVS - Display On Selection screen. 6/18/2024 249 Version: 5.19::4 Chapter 6 - Polling Place Procedures To confirm a selection, sip. The voting screen will display. 14. From there, puff to move to the next item on the screen and sip to confirm the selection. Figure 6-69: AVS - Sip-and-Puff Instructions Screen 15. Next, the voter chooses if the voting session will be presented on the screen or via audio only. Figure 6-70: AVS - Display On Selection Screen 6/18/2024 250 Version: 5.19::4 Chapter 6 - Polling Place Procedures 16. To display the ballot on the screen, select Display on by pressing the red X- shaped select button on the ATI device. 17. To activate the AVS with screen content covered by the privacy mask, select Audio only by pressing the blue down arrow button in order to highlight the Audio Only option, and then press the red X-shaped select button. Figure 6-71: AVS - Audio Only Selection Screen In Audio Only session, the privacy mask will appear on the screen, covering the content. To show the privacy mask is active, a closed eye icon appears in the upper-right corner of the screen. Audio instruction will guide the voter through the voting session. 6/18/2024 251 Version: 5.19::4 Chapter 6 - Polling Place Procedures During an audio-only session, at any time the voter can choose to deactivate the privacy mask by selecting the closed eye icon. 18. A poll worker may need to assist the voter with this action. To notify the poll worker they need assistance, the voter can press the green Help button on the bottom of the ATI. When the Help button on the ATI is pressed, a screen as displayed in figure AVS - Audio Only Selection Screen appears and the poll worker's light turns red. When the privacy mask is deactivated, the voter is informed over audio that screen content is visible to others. Press the red X-shaped select button to move to next screen. Figure 6-72: AVS - Audio Only Screen The next screen leads the voter to the voting session. The screen is divided into the following areas: • User Options/Settings (options or Display on/Audio Only sessions, Language, Text Size, Audio, Color) • Contest List (list of available contests) • Contest Description area (vote for information or ballot status: if a ballot is undervoted, overvoted, blank, etc.) 6/18/2024 252 Version: 5.19::4 Chapter 6 - Polling Place Procedures • Action buttons (Review, Back, Next, Mark and Cast) • Contest/Choice list (List of available candidates) Figure 6-73: AVS - Voting Screen Sections 19. Options in the Settings menu are available throughout the voting session. You can change language, change the text size, adjust volume and voice speed, or change the contrast settings. 20. To move between options within Settings, use the yellow left and right arrow buttons. After navigating to a new screen, the voter is read the current contest number, the total number of contests, and how to get back to the first contest (audio instructions could sound as follows: “Contest 78 of 80. Advisory Question” or “You have reached the end of the contests.”). If you want to skip a contest, you can navigate through the contest list. 21. To enter a contest, please press red X-shaped select button. To go to the contest description, press the blue down arrow. To change the user options (settings), press the blue up arrow. 22. Press the red X-shaped select button to select a candidate. To hear the list of candidates, press the yellow right arrow. To go to contest navigation and move to another contest, press the blue up arrow. To go to the Review screen, press the blue down arrow. To navigate to the contest description area, press the yellow left arrow to select the Next button. 23. From the choice list, to select a the first choice in the list, the voter presses the red X-shaped select button. To move up and down though the choice list, use the up and down blue arrows. In case of no-candidate, the voter hears the candidate’s name, but will not be able to vote for them. 6/18/2024 253 Version: 5.19::4 Chapter 6 - Polling Place Procedures 24. In case of write-in choices, select the write-in choice, and an accessible Write-In session is presented. Initially, the voter hears instructions to navigate and voting. The write-in session screen has a keyboard for entering candidate names, Clear All and Delete buttons, as well as options to Cancel and Accept selections. To move up, press the blue up arrow on the ATI. To move down, press the blue down arrow button. To move left and right, use the yellow left and right buttons. To confirm selection, press red X- shaped select button. NOTE: The Review option is available at any point during voting. Figure 6-74: AVS - Voting Screen 6/18/2024 254 Version: 5.19::4 Chapter 6 - Polling Place Procedures . Figure 6-75: AVS - Write In Screen 25. After the voter makes all selections and reaches the end of a ballot, they may review their selections. (The Next button becomes Review). On this screen the voter is informed if there are any warnings on their ballot. 26. To change user option/settings, press blue up arrow. To navigate to the first contest and review it, press the yellow right arrow. The voter hears their current selection. To change the selection, press the red X-shaped select button. 27. After completing their review, voters can press the yellow right button on the ATI to select the Mark button. This moves the voting session into the ballot marking phase. Press the red X-shaped select button to accept the selection. To move to the Back button, press the yellow left button. 28. After marking, there is a second review phase. During the second review you will not be able to make changes, since your selections are marked and 6/18/2024 255 Version: 5.19::4 Chapter 6 - Polling Place Procedures printed on the ballot. Figure 6-76: AVS - Ballot Review 6/18/2024 256 Version: 5.19::4 Chapter 6 - Polling Place Procedures Figure 6-77: AVS - Ballot Printing in Progress 29. Then, the voter has the opportunity to review the selections printed on the ballot. To move to contest list, press the yellow left button. From there, to cast the ballot, navigate to the Cast button by pressing the yellow left button. To cast the ballot, press the red X-shaped select button. To return to contest list, press the blue up arrow. When on the last contest of the list, press the blue down arrow to move to the Cast button. Press the red X- shaped select button to confirm selections (cast a ballot into the ballot box). 30. To return the ballot without casting, press the yellow left button. Then confirm by pressing the red X-shaped select button. The ballot is returned to the voter. The ballot will have printed selections, however, the ballot is not cast. 31. If voting rules violations are detected, depending on MBS options, the voter may have the option to confirm or reject casting a ballot. A pop up message shows the Cast and Reject options. For example: “You are about to cast a ballot with no marks. Are you sure you want to continue?” Available options 6/18/2024 257 Version: 5.19::4 Chapter 6 - Polling Place Procedures are: Reject and Confirm. Figure 6-78: AVS - Ballot Casting. 32. The Ballot Casting Confirmation message will appear. To continue and confirm casting the ballot, press the blue down arrow. To hear the cast confirmation warning (in case of a voting rule violation), press the blue up arrow. To navigate to the Reject button, press the yellow left button. Figure 6-79: AVS - Ballot Casting Confirmation 6/18/2024 258 Version: 5.19::4 Chapter 6 - Polling Place Procedures 33. Finally, the ballot is cast and the voting session ends. Figure 6-80: AVS - Ballot Casting 34. In case of a multi-card session, an additional screen appears, informing the voter that they can insert the next card. Press the red X-shaped select button to continue with inserting the next ballot. In case they want to cancel and finish the session, press the yellow right button. To confirm the selection, press the red X-shaped select button. 35. To proceed with voting, the screen indicating to insert a ballot appears. The 6/18/2024 259 Version: 5.19::4 Chapter 6 - Polling Place Procedures same instructions will occur as for previous ballot cards. Figure 6-81: AVS- Session Continuation 6.5.2 Accessible Voting on ICX The prerequisites for an Accessible Voting Session (AVS) are: 1. Poll worker has configured ICX tabulator to use an ATI. 2. The ATI is properly connected to ICX tabulator and fully operational. 3. An accessible session may be initiated in one of two ways: a. The voter can insert a voter smart card programmed with an accessible session. b. If Manual session activation is enabled, then a poll worker activates the voting session by entering the activation code, selecting the Enable AVS Controller checkbox during ballot activation, and then pressing Activate. 6/18/2024 260 Version: 5.19::4 Chapter 6 - Polling Place Procedures After activating the voting session and selecting the language, the applications will present a screen where the poll worker should assist the voter by selecting one of the available voting devices. . Figure 6-82: ICX - Accessible Voting Start screen 6/18/2024 261 Version: 5.19::4 Chapter 6 - Polling Place Procedures Figure 6-83: ICX - Privacy Mask Selection screen Once the AVS device has been selected, a screen will display allowing the voter or poll worker to turn the display on or off. When the display is turned off, all of the content will be blacked out except the top menu bar (with election logo and title, and the user options buttons). This privacy mask can be used to give voters the ability to vote using an assistive device in complete privacy. To activate the privacy mask, the voter or poll worker should select the Yes option. 6/18/2024 262 Version: 5.19::4 Chapter 6 - Polling Place Procedures The voter can select from the following accessibility device options: • ATI (Audio Tactile Interface) • Paddles • Sip-and-Puff • Audio/Visual mode (only available if privacy mask option is turned off) After selecting preferred device, the application will show ballot to the voter. At this point, AVS device is activated, and a voter can independently use ICX with attached AVS device to vote and cast the ballot, with no help from other persons. Optionally, if the voter selected ATI, the first screen that will be shown to a voter is “ATI Help and instructions to use.” This instructional screen describes all the functions of the ATI device and can be accessed by a voter at any time during the voting session. The "Help" dialog can be closed by pressing the Select button on the ATI device. Figure 6-84: ATI Usage Instructions 6/18/2024 263 Version: 5.19::4 Chapter 6 - Polling Place Procedures During AVS voting, all interaction with the ICX tabulator is done by using only the selected AVS device. Instructions and ballot content are played through the attached headphones. When AVS voting is activated, headphones volume is set to the configured default value. Audio volume and tempo (speed) can be adjusted by a voter at any time during the voting session by selecting the Audio button at the top of the screen. Alternatively, if the voter is using the ATI, they can adjust the audio volume and tempo (speed) by pressing two set of buttons on the ATI controller itself. The layout of buttons on the ATI controller and their functions are described on- screen and spoken. Figure 6-85: Audio options menu During AVS voting, the ballot is marked and printed by a voter using the selected AVS device. Instructions are spoken on any user interaction with the device through the headphones. According to selected device, appropriate instructions are spoken, and a voter can navigate through ballot contests and choices, as well as 6/18/2024 264 Version: 5.19::4 Chapter 6 - Polling Place Procedures configurable options for selecting language, text size, audio volume and tempo, screen colors. Also, a voter can end the voting session by choosing to cancel activation in More options menu. ® The More menu, located in the top right corner of the ImageCast X Voting interface, also offers AVS voters the following: • During a MANUALLY activated voting session: • Cancel Activation • Go to next Contest (this option allows the voter to skip a contest they do not wish to vote on) • Review your ballot (this option allows the user to proceed directly to the Review screen) • Once at the Review screen, the voter can choose from the following options: • Cancel Activation • Go to navigation bar (this option will lead the Voter to the screen navigation bar where they can choose to either print their ballot or to return to the ballot) • Once a voting session has been activated using a VOTER CARD: • Go to next Contest (this option allows the voter to skip a contest they do not wish to vote on). • Review your ballot (this option allows the user to proceed directly to the Review screen). At the review screen, the voter has the following option: • Go to navigation bar (this option will lead the Voter to the screen navigation bar where they can choose to either print their ballot or to return to the ballot). The ballot is presented in the following order during AVS voting: • Initially, the election title information is spoken. Voters will hear instructions on how to use selected AVS devices to vote for the first contest or to navigate to any other contest. • If a voter chooses to enter the first contest, the contest description and instructions on how to hear choices will be spoken. • If a voter chooses to vote for a selected contest and listen to the list of choices, the choice and instructions on how to mark a choice or navigate to the next choice will be spoken. • The Voter can repeat their decision to vote or hear the next choice until all choices of selected contest are presented. 6/18/2024 265 Version: 5.19::4 Chapter 6 - Polling Place Procedures • After hearing/selecting all available choice in a selected contest, the voter can easily navigate using either the contest navigation buttons or by using the yellow left/right arrow buttons on the ATI. • When the voter reaches the last contest, after selecting all available choices, the next screen presented is the “Ballot review.” The Ballot review screen can be navigated to at any time by using the dedicated navigation button on the bottom of the screen, or by navigating through available screen action buttons as instructed by voice instructions for selected AVS device. • In the ballot review screen the first summary ballot validation status is spoken and instructions are given to voter how to hear and review all contests, and when voter reaches last contest, an instruction is given how to print the ballot. • When a user activates command to print the ballot, a confirmation dialog is presented, and the voter has options to accept printing the ballot or to review choices by returning to review screen. • When voter accepts printing their ballot, the application shows operation information status screen and speaks success (or in case if something went wrong, warning) message. • When a voter has finished hearing the message, by navigating to and selecting Continue button, a voting session is finished, and the application redirects to the login voter screen, ready for next voter to start voting. 6.6 Provisional Voters Counties should follow their jurisdiction’s guidelines for issuing and tracking provisional ballots. Provisional ballots marked at polling places will not be ® ® scanned or tabulated by ImageCast Evolution or ImageCast Precinct 2 tabulators, instead – provisional ballots will be placed into a provisional ballot envelope and placed into the tabulator’s auxiliary bin. They will then be transported to the central elections office and tabulated there. Specific procedures may differ by jurisdiction. 6.6.1 Provisional Voting on ICE ® Provisional voters can mark and review their ballots on ImageCast Evolution. They will be provided with second chance voting if they make any mistakes that ® will be displayed on the Ballot Review screen of ImageCast Evolution when voting in the Provisional mode. The ballot will be returned to the voter and it will be placed in a marked envelope for processing in the central location after Election Day (see Chapter 12). If a provisional voter wishes to verify how the ICE will interpret their ballot, the ICE operator can activate Provisional Vote mode for the next ballot. Provisional Vote mode is identical to Ballot Review mode except that the Cast button is disabled so that the only option is to return the ballot to the voter when the review is complete: 6/18/2024 266 Version: 5.19::4 Chapter 6 - Polling Place Procedures 1. Press the iButton Security Key to the security key receptacle in order to access the poll worker mode menu. 2. Select the Provisional Vote option from the menu. This will allow the voter to insert a ballot and review their selections on the Ballot Review ® screen. The Cast button is disabled so that the ImageCast Evolution will always return the ballot to the voter to ensure that no votes are registered. In addition, depending on configuration, the provisional mode can be enabled only on next ballot or continuously. 3. To resume normal Election Run mode, the attendant must press the security key to the security key receptacle to access the Poll worker mode menu, and then select either the Standard Voting or Accessible Voting option. 6.6.1.1 Provisional Voting Using the Accessible Voting Features of the ® ImageCast Evolution If a voter requires both an Accessible Voting Session, and a provisional ballot, the following steps should be undertaken by the poll worker: ® 1. Guide the voter to the ImageCast Evolution, and log into the poll worker menu by pressing the iButton Security Key to the receptacle, and entering in the appropriate credentials. 2. Press Utilities on the left side of the screen. 3. Press Provisional Voting under the Utilities menu. 4. Press the Change button until Enabled on Next Ballot is listed as the Provisional Voting preference. 5. Activate an Accessible Voting Session, as outlined in section 6.5.1“Accessible Voting on ICE”. 6/18/2024 267 Version: 5.19::4 Chapter 6 - Polling Place Procedures At this point, the voter can begin making selections to his or her ballot. Once finished, the ballot will be returned to them at the front of the unit. It is advised that the poll worker remain in the vicinity of the voter during their Accessible Voting Session so that the ballot can promptly be placed in a Provisional Voting envelope once it has been returned. Figure 6-86: Enabling Provisional Voting 6.6.1.2 In Precinct Provisional ballots tabulated on the appropriate precinct ballot may be tabulated once their validity is verified. 6.6.1.3 Out of Precinct Provisional ballots tabulated on the incorrect precinct ballot may need to be duplicated onto the correct precinct ballot once their validity is verified. 6.6.2 Provisional Voting on ICX ® Provisional ballots will be activated on the ImageCast X in the same manner as regularly cast ballots. Poll workers should follow their jurisdiction’s procedures to ensure that the ballots marked using an ICX for a provisional voter are placed into provisional envelopes for later verification and tabulation. 6/18/2024 268 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.7 Closing the Polls and Vote Reporting 6.7.1 Closing the Polls on ICE 1. If there are ballots deposited in the auxiliary bin, insert them one-at-a-time ® into the ImageCast Evolution for tabulation. 2. Press the iButton security key against the security key reader on the ICE, then log in as a poll worker. 3. Press the Close Poll button on the Main Menu. Figure 6-87: Poll Worker Menu 4. On the Poll Management screen, press Close. 5. Enter your password and press OK. 6/18/2024 269 Version: 5.19::4 Chapter 6 - Polling Place Procedures A Close Poll confirmation screen will appear. Figure 6-88: Close Poll - Authorization Screen 6. Press OK to continue. Figure 6-89: Close Poll Confirmation Screen 7. Press OK to continue. The results tape will begin to print. You will receive confirmation that the tape has printed successfully, and you will be asked whether you wish to 6/18/2024 270 Version: 5.19::4 Chapter 6 - Polling Place Procedures print additional copies. Figure 6-90: Auxiliary Bin Prompt 8. Tear off the results tape and return it to the Election Board, complete with the signatures of Election Official. This is the Official Election Results tape. 9. Print out additional copies by pressing Yes. The required quantity of tapes is based on your jurisdiction's requirements. Figure 6-91: Printing of Result Tape Completed 6/18/2024 271 Version: 5.19::4 Chapter 6 - Polling Place Procedures ® The ImageCast Evolution's poll has now been closed. Figure 6-92: Poll-Worker Menu once Polls have been Closed 10. Press the power button in the top right corner of the screen. Select the Shut Down option to power down the unit. This action will prompt a countdown until the machine has fully powered down. Close the privacy screen flaps, and place the LCD monitor in the horizontal storage position. 6/18/2024 272 Version: 5.19::4 Chapter 6 - Polling Place Procedures NOTE: If the monitor is not placed in the horizontal storage position the system will remain in the 'stand by' mode, which expends the battery power. Figure 6-93: Power Down Request 11. Break the seal on the Ballot Box door, and unlock it using the provided key. Figure 6-94: Breaking the Ballot Box Seal 12. Remove all ballots from the Ballot Box bins. Empty the Main bin first, then remove the seal and empty the Secondary bin. Ensure that the ballots from the Main and Secondary bins (containing write-in votes) are kept separate for further, post-election day, processing at the central location. 13. Place the ballots from the two bins into separate envelopes and label them clearly, noting all necessary detail including, but not limited to, the polling location, tabulator and Ballot Box bin origin. 6/18/2024 273 Version: 5.19::4 Chapter 6 - Polling Place Procedures 14. Close the return container and seal it with a tamper-proof seal. Figure 6-95: Removing Ballots from the Ballot Box ® 15. Break the seal on the ImageCast Evolution 's CF1 door and remove the Compact Flash card. Should you wish to remove the CF2 card, do so at this time. The CF card(s) should be placed in a secure transport envelope/ case/ bag for transport to the central location. 16. This card containing the vote totals, together with all envelopes containing ballots removed from the ballot box, are transported to the Central Counting Location for accumulation and reporting of vote total results for all precincts. Figure 6-96: Removing the CF1 Card The step-by-step procedure for the Election night processing continues in chapter 8“Semi-Official Canvass Tabulation and Reporting”. 6/18/2024 274 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.7.2 Closing the polls on ICP2 After the close of voting, the poll is closed. This procedure consists of the following: • If applicable, scan ballots from auxiliary bin. • Closing the poll on the tabulator. • Printing the Results report. • Printing the Write-in report (if applicable). This procedure assumes the following: • Access to the Administrator Security Key. When instructed to do so, use the following procedure to close the poll. 1. If ballots were deposited in the auxiliary bin, insert the ballots one-at-a-time into the ICP2 for tabulation. 2. Apply the iButton to the security key receptacle and enter the password. The Main Menu screen appears. Figure 6-97: Main Menu screen 6/18/2024 275 Version: 5.19::4 Chapter 6 - Polling Place Procedures 3. On the Main menu, tap Poll Management. The Poll Management screen appears. Figure 6-98: Poll Management screen 4. Tap Close Poll and enter password. The Results Report screen appears with the Print checkbox selected. Figure 6-99: Results Report screen 6/18/2024 276 Version: 5.19::4 Chapter 6 - Polling Place Procedures 5. Tap Next. The Enter Number of Copies screen appears. Figure 6-100: Enter Number of Copies screen 6. From the Enter Number of Copies screen, tap "+" to select the required number of copies of the Results report to be printed. 7. Tap Next. If ballots with write-ins were scanned, the Write-in Report screen appears. Figure 6-101: Write-in Report screen 8. Tap Next. 6/18/2024 277 Version: 5.19::4 Chapter 6 - Polling Place Procedures 9. Indicate whether the Write-in report is to be printed and tap Next. Figure 6-102: Write-in Report screen 10. If Print was selected, tap "+" to select the required number of copies to be printed of the Write-in report on the Enter Number of Copies screen and tap Next. Figure 6-103: Enter Number of Copies screen 11. On the Close Poll Confirmation screen, tap Confirm. Figure 6-104: Close Poll Confirmation screen 6/18/2024 278 Version: 5.19::4 Chapter 6 - Polling Place Procedures 12. The poll is closed. The Printing in progress screen appears with the message “Poll Closed” in the upper left-hand corner. Figure 6-105: Printing in Progress screen The specified number of the Results reports are printed. The Printing completed screen appears. Figure 6-106: Printing Completed screen 13. At the thermal printer, tear off the Result report(s). • Process all copies of the Results report as specified by your jurisdiction. 6/18/2024 279 Version: 5.19::4 Chapter 6 - Polling Place Procedures 14. From the Printing completed screen, tap Continue. If it was decided to print the Write-in report, the Print in progress screen appears for the Write-in report. Figure 6-107: Printing in Progress screen The specified number of Write-in reports are printed. The Printing completed screen appears. Figure 6-108: Printing Completed screen 15. At the thermal printer, tear off the Write-in report(s). • Process all copies of the Write-in report as specified by your jurisdiction. 6/18/2024 280 Version: 5.19::4 Chapter 6 - Polling Place Procedures 16. From the Printing completed screen, tap Continue. The Main Menu screen appears. Figure 6-109: Main Menu screen 6/18/2024 281 Version: 5.19::4 Chapter 6 - Polling Place Procedures 6.7.2.1 Powering Down the Tabulator To power down the tabulator: 1. From the Administrator Main Menu screen, tap Utilities. 2. From the Utilities screen, tap Power Options. The Power Options screen appears. Figure 6-110: Power Options screen 3. From the Power Options screen, tap Power Down. A message appears asking to confirm powering down. Figure 6-111: Power Down screen From the message screen, click Confirm. The tabulator power downs. The tabulator is now ready for equipment take-down. 6/18/2024 282 Version: 5.19::4 Chapter 6 - Polling Place Procedures Break the seal on the Ballot Box door, and unlock it using the provided key. Figure 6-112: Breaking the Ballot Box Seal Remove all ballots from the Ballot Box bins. Empty the Main bin first, then remove the seal and empty the Secondary bin. Ensure that the ballots from the Main and Secondary bins (containing write-in votes) are kept separate for further, post-election day, processing at the central location. Place the ballots from the two bins into separate envelopes and label them clearly, noting all necessary detail including, but not limited to, the polling location, tabulator and Ballot Box bin origin. Close the return container and seal it with a tamper-proof seal. Figure 6-113: Removing Ballots from the Ballot Box Break the seal on the SD1 card door and remove the SD1 card. Should you wish to remove the SD2 card, do so at this time. The SD card(s) should be placed in a secure transport envelope/ case/bag for transport to the central location. This card containing the vote totals, together with all envelopes containing ballots removed from the ballot box, are transported to the Central Counting Location for accumulation and reporting of vote total results for all precincts. 6/18/2024 283 Version: 5.19::4 Chapter 6 - Polling Place Procedures The step-by-step procedure for the Election night processing continues in chapter 8“Semi-Official Canvass Tabulation and Reporting”. 6.7.3 Closing the Polls on ICX To close the poll: 1. In the Poll Administration menu, press Close Poll. In the Info dialog, press OK. 2. Once the Results report has completed printing, and if the MCF configurable option “Print report on close poll” is set to TRUE, you can choose one of the following options: • Save to File • Print Another Report • OK If the MCF configurable option “Print report on close poll” is set to FALSE, you can choose one of the following options: • Print report • Save to File • OK 3. Press OK. The election summary and information is printed and once finished, the VVPAT printer's light will turn off. The poll is now closed. 6.8 Securing Audit Logs and Backup Records Election audit trails provide the supporting documentation for verifying the accuracy of reported election results. They present an archival record of all system activity that is related to the vote tally. All thermal printer reports should be retained as part of the election record. The integrity of voting and audit data is kept on nonvolatile data storage ® mediums. For the Democracy Suite EMS, data is kept on hard drives. The ImageCast® voting devices and audit data are kept on the compact flash (CF) or secure digital (SD) memory cards. Hard drives, secure digital memory cards, and compact flash memory cards can be removed from the system/devices and transported to another location for readout and report generation. All tabulators maintain a real-time log of their operation, including error and audit log events. The election software application has an integrated logging service, meaning it is 6/18/2024 284 Version: 5.19::4 Chapter 6 - Polling Place Procedures active from the moment the device becomes operational. The system also has a battery-supported real-time clock (RTC), and an intrusion detection micro- controller which allows system events (such as intrusions) to be monitored and recorded off-line. The system integrates an audit log mechanism that records who did what when on the device, as well as other system level event information. 6.9 Troubleshooting 6.9.1 Operating the ImageCast® Precinct 2 on Battery The ICP2 is designed to host an internal Lithium Ion rechargeable back-up battery pack that allows the tabulator to run for over two hours in case of a power outage. When the tabulator runs only on battery, the battery icon on the LCD screen flashes. The system will shut down and preserve the integrity of votes cast prior to the power failure, and resumes functionality when power is provided or restored without significant or intrusive power-up procedures. In the event of a power failure, the equipment will continue to operate and indicate the battery life on the LCD monitor and side panel LED lights. The switch from battery power to AC power (or vice versa) takes place automatically. If the AC power is disconnected or unavailable, the unit will continue to operate on battery power as long as a sufficient charge remains in the battery. When AC power is reconnected or otherwise resumes, the ICP2 returns to AC power mode. 6.9.2 Operating the ICX on Battery In the case of power failure, the device is equipped with a backup battery and a UPS. The battery and a UPS allow the ICX device to operate for a period of two hours under normal operating conditions (100 voters per hour, and two AVS voters per hour). The switch to battery power is immediate as is the switch back to AC, once the power is restored, no special action is required. Both internal and UPS battery status is visible on ICX screen. NOTE: In case the power is lost and the machine turns off, please remove all smart cards from the smart card reader. When the machine is fully powered on, the smart cards can be inserted in the smart card reader. 6.9.3 Operating the ImageCast® Evolution on Battery In the event of external (AC/DC) power failure, this module automatically provides back-up power to the system for at least two (2) hours after which (depending on use) the battery could start running low on charge. When in use, the LCD Screen will display a battery icon indicating the battery charge level (in 6/18/2024 285 Version: 5.19::4 Chapter 6 - Polling Place Procedures %) at the bottom left corner of the screen. On the tabulator side panel, the System ON Battery LED will illuminate. The internal battery is depicted in Figure 2.12. When disconnected from the tabulator, charge level on the battery module can be identified by pressing the Fuel Gauge/Test button on the top face of the battery pack. Four LEDs on the top face of the Battery Pack provide an approximate indication of the charge level. Each LED that illuminates represents a range of 25% charge. Thus, for instance, if three LEDs illuminate, then the battery charge level is approximately 50% - 75%. NOTE: The system will not power up without a valid functional battery. Fast continuous beeps at power up provide an audible alert in the event of a non- functional battery. Figure 6-114: Internal Battery with Connectors In the event the battery charge level goes below 15%, the following audible and visual warning messages will inform the user of the battery’s condition during operational mode: • SYSTEM ON BATTERY LED will begin to flash/blink. NOTE: If external (AC/DC) power is supplied, the SYSTEM ON BATTERY LED and CHARGING LED will flash alternatingly until the battery charge level goes above 15%. • The Health Icon at the bottom of the LCD Screen will turn RED. • The LCD Screen will display an error message notifying the user of the battery charge level status. • The alert buzzer will beep twice at every 1% decrement of charge level. 6/18/2024 286 Version: 5.19::4 Chapter 6 - Polling Place Procedures NOTE: At 10% charge level, the system will issue a shut down request and power off the tabulator in order to avoid complete drain of the battery. It is therefore advisable to recharge the back-up battery or gracefully power down the system before this condition occurs. 6/18/2024 287 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures CHAPTER 7: ABSENTEE, MAIL, AND CENTRAL COUNT PROCEDURES 7.1 Preparing Absentee/Vote by Mail Ballots for Tally Ballots must be properly prepared for ballot tally. Improperly prepared ballots can cause ballot jams that result in damaged ballots. To properly inspect ballots and ® ensure the proper functioning of the ImageCast Central: • Ballots must be inspected for foreign objects such as staples, tape or paper clips. All foreign objects must be removed from the ballots. If the ballots have stubs, these should also be removed. • Folded ballots must be unfolded, oriented with folds in the same direction, and re-folded in the opposite direction, against the crease, to flatten the ballot. • Ballots must be inspected for damage, such as torn or frayed edges or cuts from opening the envelope. The readability of the ballot may be questioned if the ballot markers or voting areas on the ballot have unacceptable marks. For example: • Bad or illegible printing on the ballot. • Voter marking in the ballot ID, or ballot marker areas of a ballot. • Damaged ballot. • Wrong marking pen used (e.g. red ink or highlighters). • Greasy fingerprints, spots, or other contamination. • Incorrect ballot trimming. • All damaged or unreadable ballots should be dealt with according to 7.2 Setting up the ImageCast® Central Workstation and Scanner The following steps should be completed during Voting Phase Readiness and Logic and Accuracy Testing, but are repeated here for completeness: ® 1. Attach the power cord into to the ImageCast Central workstation and plug it into a working AC Outlet. Plug the mouse, keyboard, and iButton Security Key reader into the USB ports of the workstation and arrange them for comfortable and accessible use. 2. Plug in the scanner and attach the USB cable to the scanner's USB port on the back of the scanner. Plug the other end of the scanner USB cable to a USB port on the workstation. 6/18/2024 288 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures 3. Power on the scanner. ® 4. Power on the ImageCast workstation. ® 5. Log into the ImageCast Central workstation using the appropriate username and password. 7.3 Backing Up ImageCast® Central Files From Prior Elections ® This procedure assumes that the ImageCast Central election files were prepared and copied to the ICC workstation. Prior to loading election files ensure that the appropriate backups have been created and stored in a secure location. To backup scanned ballot images and results files from the local ICC workstation: 1. From the main Scan screen, click on Review, see Figure7-1. A list of all batches scanned by the tabulator will display. Figure 7-1: ICC - Main Scan Screen - Review option 2. To backup the results and images, click the top checkbox to select all listed batches, and then click the Export button from the bottom, see Figure7-2. 6/18/2024 289 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-2: ICC Review Screen - Select All and Export 3. A confirmation message displays. Click Confirm, see Figure7-3. Figure 7-3: ICC - Confirmation Dialog 4. Click Browse to browse to the location where you wish to save the Export, and then click Select Folder, see Figure7-4. 6/18/2024 290 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-4: ICC - Browse and Select Folder 5. The Batch Export Completed confirmation dialog displays, see Figure7-5. Click OK. Figure 7-5: ICC - Export Batches Confirmation Dialog 7.3.1 Copying Tabulator Election Files to the ICC Workstation ® Election Files are sets of folders and files that allow the ImageCast Central application to process ballots for each tabulator in the election. A unique set of election files is created by Democracy Suite EMS for each tabulator defined in the election project. The Election Files must be copied to each ImageCast Central Workstation. 6/18/2024 291 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures ® This procedure should be repeated for each ImageCast Central workstation (each physical machine). Each ICC workstation will have at least one unique set of election files—the same election files are not re-used for each ICC. NOTE: If you are resetting the system between LAT and the election, you should not set up the election files again. Instead, perform the re-zero procedure for each tabulator to delete the LAT results and reset the tabulators to zero. To copy the tabulator election files to the ICC workstation: 1. On the ICC workstation, create a folder for the project’s election files inside C:\Projects (e.g."C:\Projects\2023 GEN - ICC 1"). 2. In the newly created folder, copy all of the election files you intend to use on that ICC workstation, for example: • ICC 01 - In Person • ICC 01 - Mail-in 3. Open a second File Explorer window by right-clicking the File Explorer icon in the taskbar and selecting File Explorer. 4. In the second File Explorer window, enter \\emsserver\NAS into the address bar and then press Enter. Alternatively, in the File Explorer, under This PC, click the NAS (\\emsserver) (Z:) folder. 5. Navigate to \\emsserver\NAS\ElectionName\ElectionFiles\. In the Election Files folder, there will be one folder for each ICC tabulator. Each tabulator folder contains a unique set of election files. 6. Open the folder for the tabulator you are setting up, and select and copy all the folders and files located inside. 7. Return to the first File Explorer window and paste the copied election files into the folder you created. 8. Be sure to load all the desired tabulators on each workstation. 6/18/2024 292 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures 7.4 Loading an Election to the ImageCast® Central System The Administrator Security Key (or iButton) should be programmed for the corresponding election being configured. This Security Key is programmed from an EMS workstation. The accompanying passcode is required to use the Administrator Security Key to setup the election files for each ICC tabulator. 1. Open the ICC application by clicking on the icon pinned to the Windows taskbar. 2. If this is the first time the workstation is setup for a new election, click on the Add New button, and follow the instructions below to add a new tabulator, see Figure7-6. Figure 7-6: ICC - Add New NOTE: If a previous election was loaded on the ICC, you can select it from the Please select a tabulator drop-down menu. 3. Click the Browse button or browse to the location where you previously copied the election files. 4. Browse to the location where you saved the files and select the file folder for the ICC tabulator you wish to load. Click Select Folder, see Figure7-7. 6/18/2024 293 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-7: ICC - Browse to the location of Election Files 5. Click Continue. 6. The name of the tabulator’s folder will be pre-populated. Click Continue, see Figure7-8. NOTE: A different name may be entered for the tabulator, but it is recommended that you maintain the naming convention present in the folder as it was copied from the EMS Server. 6/18/2024 294 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-8: ICC - Enter Tabulator Name 7. A confirmation dialog will display stating that the ICC was successfully created, see Figure7-9. Click OK. Figure 7-9: ICC - Add New Tabulator Confirmation Dialog 8. The application will return to the Please Select a Tabulator screen, see Figure7-10. Click on the Tabulator from the drop-down menu and then click Continue. 6/18/2024 295 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-10: ICC - Please Select a Tabulator Screen 9. A Ready screen will display, prompting you to apply the iButton Security Key. Apply the iButton Security Key, see Figure7-11. Figure 7-11: ICC - Ready to Apply the iButton Security Key 10. Enter the password and then click the green checkmark, see Figure7-12. The application will open to the main screen and the tabulator will be loaded and ready for configuration, see Figure7-13. 6/18/2024 296 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-12: ICC - Enter Password Figure 7-13: ICC - Main Scan Screen 6/18/2024 297 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures 7.5 Configuring the Secondary or Server Path for Saving Results A secondary path should be set for saving/uploading results. If the ICC is being used with a local EMS network, then the secondary path should be set to the Central Results folder on the NAS of the EMS Server. Alternatively, the secondary/server path can be configured to a secondary location on the C drive of the local workstation or to a removable hard drive if results will be uploaded to the EMS Server manually. To configure the secondary/server path: 1. From the left navigation options, click Configure, see Figure7-14. Figure 7-14: ICC - Click Configure 2. Click the Set New Path button, see Figure7-15. 6/18/2024 298 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-15: ICC - Click Set New Path 3. A Select Secondary Path confirmation dialog will display, see Figure7-16. Click Confirm. Figure 7-16: ICC - Set Secondary Path Confirmation Dialog 4. A File Explorer window will open. Browse to the location on the NAS, see Figure7-17. 6/18/2024 299 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-17: ICC - Select Secondary Path - Select NAS NOTE: If you cannot navigate to the mapped EMS NAS location verify that the EMS Server is powered on, and that the network cable is attached. If the EMS NAS location still does not appear, the problem could be due to the local EMS network ® ® setup. Please refer to the Democracy Suite ImageCast Central Installation and Configuration Procedure document, and specifically, Sections 2.3 ICC Network Environment, 2.3.1 Planning Your Network, 6.5 Enable Network Discovery and File Sharing, and 6.3.10 Mapping the EMS NAS Folder, therein. 5. From the NAS, browse to the location of the election for which the tabulator is being configured. Then browse to the CentralResults folder within that Election's folder (create the CentralResults folder manually if it does not already exist). The Secondary Path is now set. NOTE: The option to upload results will automatically be turned on once the Secondary Path is set, see Figure7-18. This should be left on. 6/18/2024 300 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-18: ICC - Secondary Path Set - Upload Results is On 7.6 Configuring Scan Options The ImageCast Central application can be configured to behave in a user- configured manner for scanning scenarios, such as when the scanner encounters a ballot that it cannot read or various types of voting scenarios. To configure ICC scan options: 1. From the left navigation options on the main ICC screen, click Configure, and then click Settings. See Figure7-19. 6/18/2024 301 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-19: ICC - Click Configure - After Secondary Path Set 2. The first setting to apply is the Countback option. The Countback option is turned on by default. The slider bar can be moved to change the Countback option to a lower or higher number, see Figure7-20. To turn off the Countback option, toggle the 'Constant Countback' toggle switch to 'Off'. 6/18/2024 302 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-20: ICC - Settings - Countback Option NOTE: The Countback setting is a setting that causes the scanner to count an identified number of ballots any time scanning is stopped or paused mid-batch (e.g., in the event of a misread) if there are a sufficient number of ballots left in the input tray. This number can be configured so that ICC users are always required to 'countback' the same number of ballots each time scanning is paused or stopped. 3. Click on Batches to set the batch options. The options are described below and can be toggled ‘On’ or ‘Off’ as needed. a. Only one scan per batch - If turned on, users can only scan one time into each batch. If this option is turned off, users can continually add ballots into a batch once it has been started. b. Auto accept on end of day - If turned on, the ICC automatically accepts each batch after the lats card in the input tray is scanned. c. Assign poll ID to every scanned batch - If turned on, then a poll ID must be entered manually or selected before scanning. d. Manually assign batch number - If turned on, then a batch number must be manually entered before scanning. e. Use batch start cards - If turned on, then a batch start card with the Poll ID for the batch to be scanned must be included. If the batch start card is not detected, the scanner will not scan the batch. 4. Turn the desired options on or off as needed, see Figure7-21. 6/18/2024 303 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-21: ICC - Batches Option 5. Click on Stop Conditions to set any desired conditions on which the ICC should stop scanning, see Figure7-22. Figure 7-22: ICC - Stop Scan Conditions 6/18/2024 304 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures NOTE: If the Adjudication application is being used, there is no need for Election Administrators to stop scanning on various voting scenarios, other than misreads, as the Adjudication application will be used to resolve these voting scenarios. 6. Click on Ballot Configuration to set the types of ballots the scanner should be configured to accept, see Figure7-23. a. Hand Marked Ballot - regular ballots with timing marks b. Machine Generated Ballot - BMD marked, QR code ballot c. Dynamic - both hand marked and machine generated ballots Figure 7-23: ICC - Ballot Configuration 7. Selections are saved automatically. Once you have made all your selections, you can return to the main screen by clicking the Scan button from the left. 6/18/2024 305 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures 7.7 Accessing Supervisor Mode ® To access the ImageCast Central application’s Supervisor Mode: 1. From the main ICC screen, click on the Enter Supervisor Mode menu item from the lower left corner of the screen, see Figure7-24. Figure 7-24: ICC - Enter Supervisor Mode 2. When prompted by the Password Required dialog, enter the Supervisor password and then click Login, see Figure7-25. The dialog closes and the application will now run in Supervisor Mode. NOTE: You can see which mode the application is in by looking at the icon in the lower left corner of the screen, see Figure7-25. 6/18/2024 306 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-25: ICC - Enter Password to Access Supervisor Mode Figure 7-26: ICC - In Supervisor Mode 7.7.1 Canon and HiPro Scanner Imprinters The scanner imprinter, if installed, can be used to imprint details about the scanned ballot onto the ballot when it is scanned. 6/18/2024 307 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures When enabling and configuring the imprinter functionality consideration should be made to prevent the printing marks from being placed on voting targets or the orientation markers. This is managed by the ballot layout choice in conjunction with the placement of the imprinter in the scanner and the ballot orientation when scanning (portrait or landscape) as well as the type of ballot being scanned (BMD or hand-marked). Testing should be conducted with ballot samples. NOTE: Due to the imprinter settings being dependent on ballot layout and other configurations as mentioned above, please contact Dominion Voting staff for assistance when setting up the imprinters. 7.7.1.1 Canon DR-G1130 and DR-G2140 Scanner Imprinters The Canon DR-G1130 and DR-G2140 scanners imprints the following information surrounding the scanning event: • Scanning date • Scanning time • Tabulator number • Batch number • Ballot position in the batch The imprinter prints these details onto the ballot, post-scanning. For the DR- G1130, these details are also added to the ballot image digitally. Setting up the imprinter in ICC Use the following procedure to configure the imprinter in ICC. This procedure assumes the following: • Imprinter is correctly installed into the scanner • Imprinting location on the pre-printed ballots has been determined to prevent interfering with the pre-printed content • Imprinter is manually set to the necessary horizontal slot in the scanner NOTE: You should be in Supervisor Mode to change imprinter settings. To configure imprinter settings for the Canon DR-G1130 and DR-G2140 on the ICC: 1. From the main Supervisor Mode ICC screen, select Configure and then click Settings. 2. From the Scanning menu, the Imprinter settings should be available, see Figure7-27. 6/18/2024 308 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-27: ICC - Imprinter Settings - G1130 3. Set the Enable imprinting toggle switch to the ON position to activate the imprinter. 4. In the Vertical Offset field, enter a value in millimeters (mm) for where the imprinter is to print on the ballot’s vertical plane and in the ballot’s digital image. 5. From the Horizontal Offset drop-down menu, select the slot the imprinter is physically set to. This determines where the printing occurs on the ballot’s horizontal plane and in the ballot’s digital image. • If using the DR-G2140, ensure Slot 1 is selected. 6. From the Character Orientation drop-down menu, select the orientation the imprinter will print on the ballot and in the ballot’s digital image. 7. Click OK. The imprinter settings will be saved according to your selections. Imprinter Format The following is the imprinting format used when capturing the scanning details on the ballot and added to the ballot image digitally: MMM DD/YYHH:MM:SS TTTT - B - PPPP • MMM DD/YY - Date stamp of when the ballot was scanned • HH:MM:SS - Time stamp of when the ballot was scanned • TTTT - Tabulator number the ballot was scanned on 6/18/2024 309 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures • B - Batch number the ballot is located in • PPPP - Ballot’s position in the batch Example: MAR 16/1810:55:025501-1-0001 Handling Misreads If a misread occurs, do the following: 1. Using the imprinter details in the error message that displays, locate the misread ballot in the scanner’s output tray. 2. Remove the misread ballot and all proceeding ballots from the output tray. 3. Using a marking device (e.g., Sharpie Fine Point Permanent Marker), manually indicate on the misread ballot and all proceeding ballots that the imprinted content is invalid. 4. Reorient the misread ballot and all proceeding ballots so that the imprinting does not reoccur in the same location, and return them to the input try. 5. Continue scanning. 7.7.1.2 InoTec HiPro Scanner Imprinters Setting Up the Pre-scan and Post-scan Imprinters NOTE: You should be in Supervisor Mode to change imprinter settings. To configure imprinter settings for the InoTec HiPro scanner on the ICC: 1. From the Supervisor Mode ICC main screen, select Configure and then select Settings. The Scanning menu containing the Imprinter settings will display. 2. From the Scanning menu, set the Enable imprinting toggle switch to ON. The imprinter activates. To change the pre-imprinter settings (see Figure7-28): 1. In the Vertical Offset field, enter a value in millimeters (mm) for where the imprinter is to print on the ballot’s vertical plane and in the ballot’s digital image. 2. Click Change. 6/18/2024 310 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-28: ICC - Imprinter Setting - InoTec - Pre-Imprinter To change the post-imprinter settings (see Figure7-29): 1. In the Vertical Offset field, enter a value in millimeters (mm) for where the imprinter is to print on the ballot’s vertical plane and in the ballot’s digital image. 2. From the Horizontal Offset drop-down menu, select the slot the imprinter is physically set to. This determines where the printing occurs on the ballot’s horizontal plane and in the ballot’s digital image. 3. From the Character Orientation drop-down menu, select the orientation the imprinter will print on the ballot and in the ballot’s digital image. 4. Click Change. 6/18/2024 311 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-29: ICC - Imprinter Setting - InoTec HiPro Scanner- Post-Imprinter 7.8 Producing a Zero Report A Zero Report should be generated from each ICC prior to scanning ballots. The zero report can only be generated when results of the scanner are zero (i.e., no batches have been scanned/accepted). To produce a Zero Report: 1. From the left options on the main ICC screen, select the Review button. The Review screen displays, see Figure7-30. 6/18/2024 312 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-30: ICC - Main Scan Screen - Zero Results 2. At the bottom of the Review screen, click the Create Report button. The Create Report screen displays, see Figure7-31. Figure 7-31: ICC - Review Screen - Zero Batches - Click Create Report 6/18/2024 313 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures 3. To create a custom Report Header, select the toggle option titled Define Report Header, see Figure7-32. Figure 7-32: ICC - Create Report Screen - No Options Set 4. Enter the information for the report header (e.g., ‘Zero Report MM-DD- YYYY’), see Figure7-33. Click Accept. Figure 7-33: ICC - Enter Header Text for Zero Report 6/18/2024 314 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures 5. From the Report Type drop-down menu, select Zero Report, see Figure7-34. Figure 7-34: ICC - Select Report Type - Zero and Status NOTE: The Zero Report will only be available when the scanner’s results are zero. 6. From the Report Breakdown drop-down menu, select By Contest, see Figure7-35. 6/18/2024 315 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-35: ICC - Select Report Breakdown 7. Once all of your desired parameters are set, click the Generate button to generate the report, see Figure7-36. The generated report will appear on the right of the screen. Figure 7-36: ICC - Zero Report - Parameters Set 6/18/2024 316 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures 8. Click the Export button to export and save the report for printing and/or to retain alongside election records, see Figure7-37. Figure 7-37: ICC - Zero Report Generated 9. Browse to the location where you wish to save the file. By default, a file name will be generated with the report name included, but additional information can be appended or the filename can be overridden. Click Save. See Figure7-38. 6/18/2024 317 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-38: ICC - Browse to Location to Save File 10. Click the Scan button to return to the main ICC scanning screen. 7.9 Scanning Mode Scanning User Mode is the basic operator mode of the ICC application. In this mode, ballots can be scanned, scanned batches can be accepted or discarded, and the user can view information about the loaded tabulator, the ballots within the currently scanned batch (before the batch is accepted) and the 'console' or log of activities. Scanner settings and options can only be configured by Administrators and Supervisors before ballot scanning begins. Regular scanning users have limited privileges to protect the integrity of the Election Process. Administrators and Supervisors can access scanning options, settings, and configurations by attaching the iButton Security key to the iButton Security Key reader and inputting the correct passcode for that project. Once the Administrator or Supervisor removes the iButton Security Key the application security level defaults to the Scanning User mode, see Figure7-39. 6/18/2024 318 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-39: ICC - Scanning Mode Screen 6/18/2024 319 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures 7.9.1 Scanning and Accepting Batches NOTE: The scanners should be cleaned prior to scanning, after scanning, and as needed depending on the volume of ballots being scanned. If you are not already in Scan mode: 1. Click the Scan button from the left side of the ICC main screen, see Figure7- 40. Figure 7-40: ICC - Scanning Mode - with iButton 2. The iButton can be removed by the Administrator to enter the User Scanning mode (with no admin privileges). To begin scanning ballots: 1. Place the ballots in the scanner’s input tray(s). 2. Click the green Scan button on the ICC screen. The scanner will begin to scan the preloaded ballots. The ballots are scanned and images are automatically saved. 3. Click on the Ballots tab in the top right of the screen to view a list of ballots as they are being scanned in real-time. Once all of the ballots loaded into the input tray(s) have been scanned, the Accept and Discard buttons will become enabled. • Accept - Clicking this button saves the results and ballot images to the local workstation, as well as the secondary path (if defined). 6/18/2024 320 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures • Discard - Clicking this button discards the saved images and results, and returns the batch counter to its previous state. 4. To accept the scanned batch, click the Accept button, see Figure7-41. A confirmation message will appear asking the user to confirm that they wish to accept the batch, see Figure7-42. Figure 7-41: ICC - Scanning Mode - Accept and Discard Options Figure 7-42: ICC - Accept Batch Prompt 5. Click Confirm to continue accepting the batch, or click Cancel to return to the application. Clicking Confirm accepts the batch, and the ICC application then returns to the main Scan screen. 6/18/2024 321 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures 7.9.2 Scanning and Discarding Batches In some situations, users may want to discard a batch instead of accepting the batch. One example, is if a batch is accidentally placed into the input tray a second time and scanned twice. To discard a batch (prior to accepting the batch): 1. Once a batch has been scanned, and the Accept and Discard button become available. Click the Discard button. 2. A prompt appears asking the used to confirm if they would like to discard the batch, see Figure7-43. Click Confirm to discard the batch, or Cancel to return to the main scanning screen. Figure 7-43: ICC - Discard Batch Confirmation Dialog 7.9.3 Spoiling a Batch Sometimes an ICC2 operator may mistakenly accept a batch. This batch may have been incomplete, contained ballots from the wrong Counting Group, contained ballots that have already been counted or some other reason. If the batch has been scanned, but not yet accepted, discard the batch as explained in section 7.9.2“Scanning and Discarding Batches”. If a batch was incorrectly accepted and needs to be excluded from tabulation, there are two methods for removing the batch from the ICC2 itself. Additionally, if the batch has been loaded into the Results Tally and Reporting application's database (which is likely if Automatic Results Loading is being used), then the batch must also be deleted from RTR. IMPORTANT NOTE: Do not re-zero the tabulator or attempt to manually delete the batch. 6/18/2024 322 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures The ICC2 Administrator should record the number of the batch to be spoiled, and the reason(s) for spoiling the batch per the procedures established by the jurisdiction. After scanning has been completed for all ICC2 tabulators, the Election Administrator will reconcile the number of batches and ballots tabulated. NOTE: If many or all batches from a tabulator must be spoiled, please contact your Dominion Voting technical representative for assistance in resolving the issue. 7.9.3.1 Spoiling Batches Spoiling batches will remove the batches results from the ICC2’s reports and totals, but the batch will be retained on the local workstation and the Secondary Path, if set. The batch can be 'unspoiled' and re-included in the results from the tabulator, if necessary. To spoil batches: 1. From the main Scan screen, apply the iButton, and enter the Administrator passcode when prompted. 2. Enter Supervisor Mode by clicking the Enter Supervisor Mode option at the bottom left of the screen. Enter the Supervisor passcode when prompted. 3. From the left-hand side of the main Scan screen, click the Review button, see Figure7-44. The Review screen displays listing all the batches that have been scanned by that ICC. Figure 7-44: ICC - Main Scan Screen - Enter Supervisor Mode and click Review 6/18/2024 323 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-45: ICC - Select Batch to Spoil 4. Select the checkbox next to the batch or batches that need to be spoiled, see Figure7-45. 5. A confirmation dialog displays prompting the user to confirm whether they would like to spoil the batch, see Figure7-46. Click Confirm. Figure 7-46: ICC - Spoil Batches Confirmation Dialog 6. The batch will be spoiled and its status will update accordingly on the Review screen, see Figure7-47. The total batches and total ballots accepted that are displayed on the main Scan screen will be updated. 6/18/2024 324 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-47: ICC - Batch Spoiled NOTE: If desired, the batch can be unspoiled later. 7.9.3.2 Deleting Batches Deleting batches will remove scanned batch results from the ICC’s reports and totals. To delete batches: 1. From the main Scan screen, apply the iButton to enter Administrator mode and then enter the passcode when prompted. 2. Enter Supervisor Mode by clicking the Enter Supervisor Mode option at the bottom left of the screen. 3. Enter the Supervisor passcode when prompted. 4. From the left-hand side of the main Scan screen, click the Review button. 5. Select the checkbox next to the batch or batches that you wish to delete, see . Click the Delete button. 6/18/2024 325 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-48: ICC - Select Batch to Delete 6. A confirmation message displays prompting the user to confirm that they want to delete the batch, warning the user that this action cannot be undone and providing a checkbox to also delete the files on the Secondary path. See Figure7-49. Figure 7-49: ICC - Delete Batch Confirmation Dialog 7. Click Confirm. The batch will be deleted and will no longer appear on the Review screen in the list of batches. The existing batch numbers will remain unchanged. The total batches and total ballots accepted that are displayed on the main Scan screen will be updated. 6/18/2024 326 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures NOTE: If the batch was already loaded into RTR, then the EMS/RTR Administrator must also delete the batch from RTR. Instructions for doing so are provided in the Democracy Suite® EMS Results Tally & Reporting User Guide, Section 8.4 Deleting of Results. 6/18/2024 327 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures 7.9.4 Producing Reports from the ImageCast® Central System and Closing the Tabulator 7.9.4.1 Generating a Status Report During ballot scanning, a Status Report can be produced from each ICC workstation in use. This report may be useful for balancing and auditing purposes. To produce a status report: 1. Enter Administrator Mode by applying the iButton and entering the Administrator passcode when prompted. 2. Click the Review button, see Figure7-50. The Review screen displays, listing all batches scanned by the tabulator. Figure 7-50: ICC - Review Button NOTE: Once batches are deleted, they will no longer display on this screen. Spoiled batches will display, but they will not be included in the report(s). 3. From the list, click on the batches you wish to generate a report for, and then click the Create Report button, see Figure7-51. The Create Report screen displays, featuring a set of report settings options. 6/18/2024 328 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-51: ICC - Review Screen 4. Select the options you would like to use to generate the report (see Figure7- 52 for reference): a. Report Header - Field used to enter custom text for a header b. Report Type - Drop-down menu including: • Status Report • Zero Report • Results Report Select Status Report, as Zero Report is only available when results are zero, while the Results Report is only available when the tabulator is closed. c. Report Breakdown - Drop-down menu including the following options: • Overall Total • Batch by Batch ID • Batch by Date d. Results Display - Toggle switch buttons that, if set to ON, allow you to: • Show list of precincts in reports header • Show ballots cast on the reports 6/18/2024 329 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-52: ICC - Status Report Options 5. After making all the appropriate selections, click the Generate button. The Status Report will generate. This report will display only the totals of ballots scanned, based on the breakdown selections made (i.e. By Date, Batch ID, or Overall Total), see Figure7-53. 6/18/2024 330 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-53: ICC - Status Report Generated 6. Click the Export button to export and save a copy of the report(s) for retention. 7.9.4.2 Closing the Tabulator At the end of scanning, the ICC2 tabulator can be closed. To close the ICC2 tabulator: 1. Enter Administrator Mode by applying the iButton and entering the Administrator passcode when prompted. 2. Click the Configure button from the left pane, see Figure7-54. 6/18/2024 331 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-54: ICC - Click Configure to Close 3. Click the Close button, see Figure7-55. Figure 7-55: ICC - Click Close 4. A confirmation dialog displays, Figure7-56. Click Confirm. The ICC2 tabulator is now closed. 6/18/2024 332 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-56: ICC - Close Tabulator Dialog 7.9.4.3 Generating a Results Report When the tabulator is closed, a Results Report can then be generated. NOTE: The ICC2 tabulator must be closed to generate the Results Report. To generate a Results Report: 1. From the left navigation pane, click the Review button, see Figure7-57. The Review screen displays, featuring a list of batches. Figure 7-57: ICC - Click Review 6/18/2024 333 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures 2. Click on the batches you wish to generate a report for, and then click the Create Report button, see Figure7-58. The Create Report screen will display featuring a set of report settings options. Figure 7-58: ICC - Generate Results Report NOTE: Once batches are deleted, they will no longer display on this screen. Spoiled batches will display, but will not be included in the generated report(s). 3. Select the options you would like to use to generate the report, including: a. Report Header - Field used to enter custom text for a header b. Report Type - Select Results Report from the drop-down menu c. Report Breakdown - Drop-down menu including the following options: • By Contest • By Precinct • By Ballot ID d. Results Display - Toggle switch buttons that, if set to ON, allow you to: • Show list of precincts in reports header • Show ballots cast on the reports 4. After making all the appropriate selections, click the Generate button. The Results Report will generate, see Figure7-59. 6/18/2024 334 Version: 5.19::4 Chapter 7 - Absentee, Mail, and Central Count Procedures Figure 7-59: ICC - Results Report Generated 5. Click the Export button to export and save a copy of the report(s) for retention. 6/18/2024 335 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting CHAPTER 8: SEMI-OFFICIAL CANVASS TABULATION AND REPORTING This chapter contains suggested procedures that will be a part of a jurisdiction’s Election Night standard operating procedures. 8.1 System Start-up and Pre-tabulation Report Procedures 8.1.1 Start EMS RTR To start the EMS Results Tally & Reporting (RTR) application: 1. Double-click on the Results Tally & Reporting icon on the desktop. If this is the first time opening Results Tally & Reporting, the Localization Settings dialog will appear. 2. Select Default as the language option, and click OK. The EMS Results Tally & Reporting application opens. 6/18/2024 336 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting 8.1.2 Open Project To open your Election Project in Results Tally & Reporting: 1. Open the EMS Results Tally & Reporting application. 2. Expand the Election Project item from the Main Menu and click Open Project. Figure 8-1: EMS Application Server Settings Screen NOTE: If you are opening the project for the first time, you must set the network parameters in the EMS Application Sever Settings window that appears, see Figure8-1. Enter all the required data for the fields listed below: EMS Application Server Host (IP Address or Name): Enter the name of the EMS application server host. EMS Application Server Name: Enter emsapplication- server. 3. Once all data is entered, click Test. If the settings are correct, you will receive confirmation in the gray dialog box. If you do not receive a confirmation, correct your settings, or contact your IT personnel for the proper credentials. Click the OK button to continue. The Open Project screen appears. Click on the desired project to select it, and then click on the OK button. NOTE: Only election projects with a ‘Ready for Election’ status can be opened in the Results Tally & Reporting application. If an election project is not in the ‘Ready for Election’ status, the election files have not yet been created for that project, and therefore election result files cannot be processed. NOTE: The EMS Results Tally & Reporting Application User’s status must be activated in the EMS Election Event Designer application. 6/18/2024 337 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting 4. In the election project Login dialog window, type in the credentials for the Results Tally & Reporting Administrator and then click OK. See Figure8-2. If you do not have the credentials, contact your supervisor. Figure 8-2: Login Screen 5. After successfully logging into the EMS Results Tally & Reporting application, the application expands to include new menu items and the status bar is updated to contain project and user details. 8.1.3 Run Zero Report To verify that there are no published results in the database and to generate a Zero Report: 1. Expand the Reports menu and click Results Reporting. 2. In the Report Group field, choose Election Day Reports. 3. In the Report Name field, choose Summary Report (2 column). 4. Apply the following settings: Statistics: • Show X of Y at the top of the report for whole elections = set to True Turnout: • Show registration and turnout = set to True Write-ins: • Include qualified write-ins = set to True* • Include write-ins = set to True* *If desired (these settings are optional). 6/18/2024 338 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting 5. Click Create Report. Wait until the report is created and verify that the total results are zero. Print and/or save the report to maintain the necessary election records. NOTE: If the Zero report is showing any results, notify the Administrator immediately. 8.2 Processing Vote Reports The following procedures assume the following: 1. That the RTR User has been created and activated (refer to 12.2.7“Creation of RTR User in Election Event Designer”) in the EED application. If you have received the project from Dominion Voting Systems, the RTR User would have already been set up in the Election Project and the RTR user name and password details would have been provided to the jurisdiction together with the Election Project package. If the jurisdiction is programming their own election project, the EMS Administrator will set up the RTR user. 2. Network parameters have been configured. This should have been set up during the Installation, Readiness, and L&A procedures. 3. Reporting services are initialized as would be done during the installation procedure (refer to 12.2.8 “Initializing Reporting Services”). 4. Any pre-existing results (such as results generated during the L&A procedures) must be purged by the Administrator (refer to 4.5.5“Clearing Logic and Accuracy Test Results”). 8.2.1 Loading Results from Removable Media Management NOTE: In order to load results, make sure to install File System Service (please see ® the Democracy Suite EMS Results Tally & Reporting User Guide). To load results from Removable Media Management: 1. Connect the card reader/writer to the EMS Results Tally & Reporting workstation. 2. Within the RTR application, expand the Actions menu and then click Removable Media Management. 6/18/2024 339 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting The Load Results dialog appears, as seen in Figure8-3. Figure 8-3: Load Results Dialog NOTE: If the Use test results option was checked in the Project Settings - Project Parameters dialog, the header will contain a post fix "- Testing Mode" to indicate that only TEST result files can be loaded. 3. Select one of the following options from the Actions field: • Load Results file • Load Ballot Images • Load Log File 4. If you do not want loaded results to be available for Adjudication, select Skip Adjudication. 5. Click Start Loading to import the selected type of file. 6. Insert the removable medium into the card reader. 6/18/2024 340 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting Figure 8-4: Load Results dialog 7. The Process window tracks the loading progress for the selected file type. The Load Result dialog contains a record of the completed action, as seen in Figure8-5. If results are successfully loaded, you may then eject the memory card. Figure 8-5: Load Results dialog 8. It is possible to load the result files, ballot images, and log files separately. For instance, If you want to load only ballot images, you need to enable Load Ballot Images and make sure that other check boxes under Actions are cleared. This procedure is the same for Load Results File and Load Log File: 6/18/2024 341 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting 1. Insert the memory card into the card reader. 2. The Load Results dialog appears, displaying a record of the completed action, see Figure8-6. Figure 8-6: Load Results dialog 3. This process should be repeated until all results are loaded. 4. The Load Results dialog contains all relevant information. Possible results scenarios include: • If the results file has already been loaded into the EMS Results Tally & Reporting application, the Load Results dialog will display an error message, as seen in Figure8-7. Figure 8-7: Load Results Dialog • Likewise, if the ballot images or log files you are trying to load have 6/18/2024 342 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting already been loaded into the EMS Results Tally & Reporting application, the Load Results dialog displays information that loading is being skipped. Figure 8-8: Load Results Dialog • To overwrite ballot images, enable Overwrite Ballot Images. To overwrite log files, enable Overwrite Log File. • To load new results files for the same tabulator, delete the previous result file. This can be accomplished in one of two ways: 1) Delete Result Files, or 2) Purge Results. • If the removable medium was dismounted during loading, an error message will appear, as shown in Figure8-9: Figure 8-9: Load Results Dialog 6/18/2024 343 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting • Re-insert the removable medium into the card reader. 5. When complete, close the dialog. 8.2.2 Load Results from Directory 1. Click Actions and choose Load Results From Directory. The Load dialog appears. 2. Click Browse to browse to the source directory. 3. Expand Computer and browse to the local folder where the results are saved (for example Z:\Project Name\Results\Tabulator x x x x x\Results folder). 4. Click OK. 5. Leave file types as Results. If the results to be loaded should NOT be adjudicated, select the Skip Adjudication check box. If the results to be loaded are to proceed to adjudication, then leave the check box unchecked. 6. Select the files you wish to load and then click Load. NOTE: When you select the tabulator folder to load results from, make sure that the “Show Loaded Files” check box is selected. The result files that were already loaded will be listed in the window with a “Load” column checked. Select only the result files that have not been loaded and then click OK. If you try to upload result files that have already been loaded, a message will display notifying you that results already exist in the database. 7. Once all result files have been loaded, click OK. 8. Repeat steps 2 through 7 to import results for each tabulator, taking care to select the Results folder within the desired tabulator folder in step 3 above. 9. Click Close to close the dialog. 8.2.3 Automatic Result Loading This section explains how to load the election results automatically. To automatically load results: 6/18/2024 344 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting 1. Select Actions from the top bar menu of the RTR application main screen and click on the Automatic Result Loading option. The Automatic Result Loading dialog appears, as seen in Figure8-10. The ‘Automatic Result Loading’ setting is divided into two sections: 1) Service Settings and 2) Service Status. Figure 8-10: Automatic Result Loading dialog 2. Set the following Service Setting options: • Results Directory - RTR can automatically load results from two predefined locations: • Results directory - select option Central Scanning from the drop-down menu. • Uploaded Results directory (results loaded from Listener). 3. Service Status displays the status (started or stopped), loaded, and total number of result files in the selected results directory. 4. Click the Start button to start automatic loading. 5. Click Refresh to refresh Service Status information. 6. Click on the Stop button to stop automatic result loading. 7. Click Close to close the dialog. 6/18/2024 345 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting 8.2.3.1 Automatic Images Loading To automatically load images: 1. From the Automatic Results Loading screen, check the box Load Images. 2. Click Start in order to start service (automatic loading). 3. Click Stop in order to stop service. 4. Click Refresh to update service status: • Is it running or not • Number of loaded batches 5. When you click Close, the screen closes. 8.2.4 Validate and Publish Results Results must be in a Published state in order to report them. To publish a selection of result files (that are in Initial state): 1. Select Result Files in the left hand menu bar. The Result Files main activity screen appears. 2. Tabulator, Tabulator Type, and Result State drop-down menus may be used to filter the search results. 3. Click Search to list results. 4. Select all results that you wish to include in the reports, and then click Validate & Publish. 5. Click Yes to confirm your action in the Question dialog that appears. 6. Click Close in the Information dialog that appears once the process is complete. 8.2.5 Election Night Summary Report - Election Day Report To create Election Summary Report, do the following: 1. Expand the Reports menu and click Results Reporting. 2. In the Report Group field, choose Election Day Reports. 3. In the Report Name field, choose Summary Report (2 column). 4. Select the desired criteria in the ‘Options’ section located on the right of the screen. Click the Create Report button to generate the report. This may take a while, depending on the size of election. 5. The report will be generated and should appear in the list of generated reports at the center of the screen. 6. To export and save the report, click on the desired row, and then click the 6/18/2024 346 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting Export button from the center of the screen. 7. The Windows browse dialog window will appear. Navigate to the location where you want to save the report, enter the file name and then click on the Save button. 8.2.6 Central Tabulation Report preliminary Absentee and All Mail ballot results that were scanned on the Absentee/All Mail ICC, up until the jurisdiction’s reporting ‘cutoff’ point. 1. Open the EMS Results Tally & Reporting (RTR) application (refer to 8.1.2“Open Project”). If the project was created by Dominion Voting, the RTR user name and password will be provided to the jurisdiction. Jurisdictions programming their own elections will have to have their Administrator create an RTR user (refer to 12.2.7“Creation of RTR User in Election Event Designer”) in EED application. 2. Open the appropriate Election Project (refer to 8.1.2“Open Project”) and enter your login credentials. 3. Run the Zero Report from the RTR (refer to 8.2.1“Loading Results from Removable Media Management”). NOTE: If automatic loading of results is used and Adjudication is a part of the workflow, then the RTR will already contain adjudicated results.The results will automatically be loaded into RTR and updated after Adjudication. 4. If automatic results loading is not used, then load the results files, audit log files and result images (refer to 8.2.2“Load Results from Directory”) (if enabled and required) from the ICC tabulators that are not automatically loaded into the RTR application. NOTE: When loading results from any ICC tabulator on election night, ensure that the Skip Adjudication check box is selected. On Election Day, only the Results files should be loaded into RTR, since images can prolong the loading process. Once all result files are uploaded, return here and continue with the next step. 5. Validate and publish results files (refer to 8.2.4“Validate and Publish Results”) in the RTR application. 6. After the Closing of Polls, and after the Early Vote and Election Day ICE and ICP2 results have been loaded (refer to 8.2.2“Load Results from Directory”) to the RTR application, run the Election Day Reports. 6/18/2024 347 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting ® 8.2.6.1 Early Vote ImageCast Evolution and ImageCast® Precinct 2 Report preliminary Early Vote ballot tally results that were scanned up until the jurisdiction-defined ‘Cut Off’ point in time as previously mentioned in sections ® ® 6.4.1 “ImageCast Evolution” and 6.1.3 “ImageCast Precinct 2 and Related Equipment”: 1. Unpack the CF and SD cards from the Early Vote tabulators and identify the CF or SD1 card for that tabulator to be uploaded. 2. Open the EMS Results Tally & Reporting 8.1.2“Open Project” application. If the project was created by Dominion Voting, the RTR user name and password will be provided to the jurisdiction. Jurisdictions programming their own elections will have to have their Administrator create an RTR user account and activate (refer to 12.2.7“Creation of RTR User in Election Event Designer”) it in EED. 3. Open the appropriate Election Project (refer to 8.1.2“Open Project”) and enter your login credentials. 4. Load the results files, audit log files, and result images (if enabled and ® required) from all early voting ImageCast Evolution tabulators into the RTR application. NOTE: When loading results from any Early Vote tabulator, ensure that the Skip Adjudication check box is selected. On Election Day, only the result files should be loaded into RTR, since images can prolong the loading process. Once all result files are uploaded, continue with the next step. 5. Validate and publish (refer to 8.2.4“Validate and Publish Results”) results files in the RTR application. ® 6. After the Closing of Polls, and after the Election Day ImageCast Evolution and ICC results have been loaded to the RTR, run the Election Summary Report (refer to 8.2.5“Election Night Summary Report - Election Day Report”). 8.2.7 Precinct Tabulation (ICE and ICP2) After closing of polls on Election Day, the results from precinct ICE and ICP2 tabulators are loaded into RTR as they start arriving to the central processing location. 1. Unpack the CF and SD cards from the Election Day precinct tabulators and locate the CF1 or SD1 cards for the tabulator to be uploaded. 2. Open the EMS Results Tally & Reporting (refer to 8.1.2“Open Project”) application (referred to here as RTR). If the project was created by Dominion Voting, the RTR user name and password will be provided to the 6/18/2024 348 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting jurisdiction. Jurisdictions programming their own elections will have to have their Administrator create an RTR user account and activate it in EED as described in Creation of RTR User in Election Event Designer (refer to 12.2.7“Creation of RTR User in Election Event Designer”). 3. Open the appropriate Election Project (refer to 8.1.2“Open Project”) and enter your login credentials. Load the results files, audit log files and result images (if enabled and required) from Election Day ICE and ICP2 tabulators into the RTR application (see “Loading Results from Removable Media Management” on page339). NOTE: When loading results from any Election Day tabulator, ensure that the Skip Adjudication check box is selected. Once all result files are uploaded, return here and continue with the next step. On Election Day, only the Results files should be loaded into RTR, since images can prolong the loading process. 4. Continue loading the results as the CF and SD cards arrive until pre- determined points in time are reached, at which result files loaded until that point are published and reported on. 5. Validate and Publish (refer to 8.2.4“Validate and Publish Results”) those results. 6. To find out how many precincts have been reported on, as opposed to how many are still due to be loaded into the RTR, run the ‘Tabulator Status’ report: a. Under the Reports menu click Results Reporting. In the Results Reporting, under Basic group you can find Tabulator Status report. b. In the ‘Report Name’ drop-down menu, select ‘Tabulator Status’, and then click on the Create Report button. c. The success dialog window will appear when the report is complete. d. Click OK and then click Search to list reports. e. Double-click on the newly created report to open it. Inspect the ‘Load Status’ and ‘Total Ballots Cast’ columns to determine which precincts are missing from the report. 7. Continue the process of loading, publishing, and reporting the results from the Election Day ICE and ICP2 tabulators in regular intervals until all results are loaded. ® 8. After all results from Election Day ImageCast Evolution, Election Day ImageCast® Precinct 2, and ICC tabulators have been uploaded, run the Election Summary Report (refer to 8.2.5 “Election Night Summary Report - Election Day Report”) again to obtain the Final Election Night Summary Report. 6/18/2024 349 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting 8.2.8 Precinct Tabulation (ImageCast® X) ® ® ImageCast X produced ballots need to be run through ImageCast Evolution, ® ImageCast® Precinct 2 or ImageCast Central tabulator in order to be counted. Once the ballot is scanned, the results are tabulated and indistinguishable from pre-printed, hand-marked ballot results. See section 8.2“Processing Vote Reports” or section 8.2.7 “Precinct Tabulation (ICE and ICP2)” for more information on tabulation. 8.3 Integration with County Systems and Calvoter/ VoteCal This section outlines the procedure for configuring RTR to enable Auto- Reporting. Prerequisites: 1. Election Project Package is restored to the RTR/Tabulation server. 2. Auto-Reporting Templates from the SOS. The state will send your county templates during pre-Logic & Accuracy Testing. The templates should consist of text files, see Figure8-11. Figure 8-11: Auto-Reporting Template text files 3. Copy the templates to the folder below the NAS of your RTR/Tabulation server (see Figure8-12): \NAS\Project Name\Reports\Templates Figure 8-12: Templates in NAS folder on RTR/Tabulation server 6/18/2024 350 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting The following steps outline the procedure for importing the template text files into RTR in order to set up Auto-Reporting. The procedure is broken down into four main parts: 1. Load Mappings and Templates 2. Verify and Edit Contest Mappings 3. Verify and Edit District Mappings 4. Create Report 8.3.1 Load Mappings and Templates To load mappings and templates into RTR: 1. Copy the templates to the RTR/Tabulation system workstation. 2. Log into the Results Tally and Reporting (RTR) application. 3. From the top menu, select Actions, and then select Sos Mapping. See Figure8-13. Figure 8-13: Results Tally and Reporting - Actions tab 4. The SOS Mapping window will display, as shown in Figure8-14. 6/18/2024 351 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting Figure 8-14: SOS Mapping window 5. Select Load Template File, see Figure8-15. Figure 8-15: SOS Mapping screen- Load Template File 6. Select the pp text file. A success message dialog will display, as seen in Figure8-16. Click OK. Figure 8-16: Operation Success dialog 7. From the SOS Mapping window, select Load Template File. 8. Select the DP text file. A success message dialog will display. Click OK. 6/18/2024 352 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting 9. From the SOS Mapping window, select Load Mappings. The contents of the templates will load. See Figure8-17. a. The contests within the mapping templates will be listed on the left-hand side of the SOS Mapping window. b. The contests within the EMS database will be listed on the right-hand side of the SOS Mapping window. Figure 8-17: SOS Mapping screen- Load Mappings 10. Select the Auto Mapping button, see Figure8-18. Figure 8-18: SOS Mapping screen - Auto Mapping NOTE: Many contests and districts will map automatically. All mappings should be verified for validity. 6/18/2024 353 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting 8.3.2 Verify and edit contest mappings To verify and edit contest mappings, follow these steps: 1. Verify that entries listed under ‘External Contest Name’ match entries listed under ‘Linked EMS Contest’. See Figure8-19 and Figure8-20. Figure 8-19: SOS Mapping screen - External Contests Figure 8-20: SOS Mapping screen - External Contest Name list 2. Verify that entries listed under ‘External Candidate’ match entries listed under ‘Linked EMS Candidate’. See Figure8-21. Figure 8-21: SOS Mapping screen - External Candidate and Linked EMS 6/18/2024 354 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting Candidate lists 3. If an object is mapped incorrectly: a. Unlink the incorrect object: Select the contest or candidate from the list on the left of the SOS Mapping window, and then click on the UnLink button. See Figure8- 22. Figure 8-22: SOS Mapping - Unlinking incorrect object b. Next, link the correct object: Select the appropriate contest or candidate from the right of the SOS Mapping window, and then click the Link button. See Figure8-23. Figure 8-23: SOS Mapping - Linking correct object 6/18/2024 355 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting c. Link the object’s choices: Select each choice from the desired list on the left side of the SOS Mapping screen (i.e., the ‘External Candidate’ or ‘External Contests’ list), and then select the corresponding choice from the right side (i.e., from the ‘EMS Contests’ or ‘Available EMS Candidates’ list). Click the Link button to link the selected candidates/choices. See Figure8-24. Repeat this procedure until all choices are appropriately mapped. Figure 8-24: SOS Mapping - Linking Candidates/Choices 4. If an object is not mapped automatically: a. Select the contest that is not mapped from the left side ‘External Contests’ list. b. Select the contest in order to map it to from the right side ‘EMS Contests’ list. c. Select the Link button. NOTE: Qualified write-ins will not be contained in the first report (the election night report). The state will include qualified write-ins in the SOV reports. 5. To save your settings, click the Save Changes button located at the top- right of the SOS Mapping window. 8.3.3 Verify and edit district mappings To verify and edit district mappings in RTR, follow these steps: 1. Click on the Map Districts tab. 2. Verify that entries listed under ‘External District Name’ match entries listed under ‘Linked EMS District’. See Figure8-25. 6/18/2024 356 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting Figure 8-25: SOS Mapping - Matching External District Name and Linked EMS District 3. To add or change a mapping: Select the district from the left side ‘External Districts’ list, then select the appropriate district from the right side ‘Available EMS Districts’ list. Click the Link button to link the selected districts. See Figure8-26. Figure 8-26: SOS Mapping - Add/Change a mapping 8.3.4 Create Report To create a report based on the settings outlined in this section, follow these steps: 1. From the SOS Mapping window, select Create report. See Figure8-27. 6/18/2024 357 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting Figure 8-27: SOS Mapping - Create Report 2. Select the Report Template, Report Type, and Counting Group from the corresponding drop-down menus, see Figure8-28. Figure 8-28: Create SOS Report dialog Here is a list of Report Types to choose from: • REGL = Election Night • FINL = Final report of election night • UPDT = Updates results through the Canvass/Certification Period • SOV = Report format for post-certification* • SSOV = Report format with detailed summary of votes cast by jurisdiction for post-certification* *Certified write-in candidates will need to be added and mapped prior to running the SOV/SSOV. 3. Click Create Report. This will prompt you to save the report, see Figure8- 29. After saving the report, upload it to the SOS. 6/18/2024 358 Version: 5.19::4 Chapter 8 - Semi-Official Canvass Tabulation and Reporting Figure 8-29: SOS Mapping - Save As dialog 6/18/2024 359 Version: 5.19::4 Chapter 9 - Adjudication CHAPTER 9: ADJUDICATION 9.1 Adjudication Overview The Adjudication application can be used to resolve common voting scenarios, including resolving write-ins, marginal or ambiguous marks, and overvotes. While ballot adjudication is in progress, users receive ballots to adjudicate based on the filtering conditions set up by the administrator in the Project Setup Wizard. Ballots may be provided to adjudication users using one of two methods: a. Ballots can be automatically sent to users as they become available. b. Ballots may be sent to users as batches are assigned to those users. Adjudication Users and Adjudication Administrators may adjudicate ballots. 9.1.1 Adjudication Workflow When Election Administrators are ready to prepare for and eventually initiate Adjudication for an election, the following workflow should be followed: 1. Create Adjudication Administrators and Adjudication Users 2. Assign Elections to Users 3. Create Adjudication Profile(s) 4. Start Adjudication Session 5. Adjudicate Ballots 6. Batch Management 9.2 Create Adjudication Administrators and Adjudication Users Adjudication Users can only be created by Adjudication Administrators or Technical Support Users. When these users are logged into the application, they can access a Users menu item where they can create new users, edit existing users, and assign elections to users. Refer to Chapter 2 of the Adjudication User Guide for more information on User roles and privileges, as well as how to log into the Adjudication application for the first time. 9.2.1 Accessing the Users Screen/Menu Item Once an Administrator is logged into the application, they can access a Users menu item. To access the Users screen: 6/18/2024 360 Version: 5.19::4 Chapter 9 - Adjudication • From the left navigation pane, click on the Users item (see Figure9-1). A list of the already existing users will display (see Figure9-2). Figure 9-1: Adjudication - Access Users Menu Figure 9-2: Adjudication - List of Existing Users 6/18/2024 361 Version: 5.19::4 Chapter 9 - Adjudication 9.2.2 Creating New Users To create new users in the Adjudication application: 1. From the right corner of the User List pane, click the Create New button (see Figure9-3). Figure 9-3: Adjudication - Create New User 2. Enter the relevant information for the new user (see Figure9-4 for reference): • Username: Field where you can enter the name that will be used to log into the application. • Display Name: Field where you can enter the name that will display for the user on their User Preference menu. • Assigned Role: Drop-down menu where you can select the level of privileges the user has access to, including the following options and their corresponding privileges: • Adjudicator can adjudicate ballots • Administrator can adjudicate ballots, review ballots adjudicated by other users, perform batch management functions, and perform user management functions • Technical Support can adjudicate ballots, review ballots adjudicated by other users, perform batch management functions, and view scheduled actions from the actions list. 6/18/2024 362 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-4: Adjudication - Create User Settings 3. Once you have set the relevant user credentials, click Submit to create the new user (see Figure9-5). Figure 9-5: Adjudication - Create User - Click Submit 4. A confirmation message will display at the top of the screen as will the user's temporary password (see Figure9-6). Write this password down and provide it to the new user. They will be required to reset their password upon logging into the application for the first time. 6/18/2024 363 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-6: Adjudication - Create User - Temporary Password NOTE: If the password is forgotten, or if a User's password needs to be reset - refer to Chapter 3, Section 7 of the Adjudication User Guide for details about resetting passwords in the Adjudication application. 9.3 Assigning Elections to Users Administrators must assign Elections to users for those users to be able to adjudicate or perform administrative activities on an election. Follow the steps outlined in the subsections below to assign an election to a user. Once the user has been assigned an election, they will be able to interact with that election's adjudication session based on their assigned user role. This step should be completed prior to the adjudication of Logic and Accuracy Testing ballots, and prior to the adjudication of any live ballots, for each election. 9.3.1 Assigning Users to an Election from the Users Screen To assign users to an Election Project from the Users screen: 1. From the left navigation pane, click on the Users item. The list of users will display. 2. In the User list panel, click on the Assign Election Event button associated to the existing user you want to assign an election to (see Figure9-7). 6/18/2024 364 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-7: Adjudication - Users - List of Existing Users to Assign 3. Click on the election name you wish to assign, and then click the Submit button (see Figure9-8). A green success message will display in the top right corner of the screen, confirming that the user is successfully assigned to the selected election project. Figure 9-8: Adjudication - Assign Election Event to User 9.3.2 Assigning Users to an Election from the Election Event Screen To assign users to an election project from the Election Event screen: 6/18/2024 365 Version: 5.19::4 Chapter 9 - Adjudication 1. From the main Adjudication screen, the Adjudication Administrator (or Technical Support User) must click on the Election Events option (see Figure9-9). The elections that the Administrator has available will display. Figure 9-9: Adjudication - Click Election Events NOTE: If an Election does not display here, verify that the Election is assigned to the Administrator and that Adjudication is enabled in RTR. 2. Click the Assign Users button associated to the Election you wish to assign the user to, see Figure9-10. A list of existing users displays under the chosen Election Project name. Figure 9-10: Adjudication - Assign Users Button 3. The Administrator should select the users they wish to assign, and then click the Submit button (see Figure9-11). The selected users are now assigned to the chosen Election Project. 6/18/2024 366 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-11: Adjudication - Assign Users to Election Events 9.4 Creating Adjudication Profiles Adjudication Profiles can be used to configure a set of saved options and settings prior to an election, and can then be reused for each election to ensure that the same settings are used for each adjudication session necessary. Adjudication sessions can be started without adjudication profiles, however adjudication profiles are recommended to ensure that consistent settings are used for all adjudication sessions. Only Administrators and Technical Support Users can create Adjudication Profiles. NOTE: Adjudication settings may vary depending on the type of election, for example - a Recount Election may need to include filtering options for undervotes and blank contests. In this case, an Adjudication profile can be defined for 'Standard Adjudication Sessions' and an Adjudication profile can be defined for 'Recount Adjudication Sessions'. To create an Adjudication profile: 1. From the left navigation menu, select the Adjudication profile option (see Figure9-12). 6/18/2024 367 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-12: Adjudication - Select Adjudication Profile 2. A list of existing Adjudication profiles will display (if they exist). Click Create new to create a new Adjudication profile (see Figure9-13). Figure 9-13: Adjudication Profile - Create New 3. The profile creation wizard will open. In the first section, titled Basic Data, input the Name of the profile and a description for the profile, and then click Next. See Figure9-14. 6/18/2024 368 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-14: Adjudication - Create Profile Name 4. From the Ballot Filtering & Highlighting screen, select the options for filtering ballots (see Figure9-15 for reference): • Adjudicate all ballots: Selecting this option will present all ballots, regardless of voting conditions met for review by an adjudicator. • Common filtering and highlighting options for all ballots: Selecting this option will allow the Administrator to define one set of filtering (outstack) criteria for all ballots that are tabulated in the election. • Separate filtering and highlighting options per tabulator type group: Selecting this option will allow the Administrator to define one set of filtering (outstack) criteria to be used when presenting ballots from central count tabulators and one set of filtering (outstack) criteria to be used when presenting ballots from Precinct (in-person) tabulators. 6/18/2024 369 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-15: Adjudication - Ballot Filtering & Highlighting Radio Buttons 5. After selecting the Ballot Filtering & Highlighting options, select the filtering (outstack) criteria to be used and then click Next (see Figure9-16). Figure 9-16: Adjudication - Create New Profile - Filtering Options Understanding Filtering Options/Outstack Criteria The following tables explain the filtering options/outstack criteria for both Standard Voting and Rank Choice Voting, respectively: 6/18/2024 370 Version: 5.19::4 Chapter 9 - Adjudication Name Description This option will outstack any contests that has at least one Ambiguous choice that was detected as a marginal mark. This option will outstack any contest that has at least one less selection made than the 'Vote For' value defined for Undervote that contest. This option will outstack any contests where a write-in Write-in position is marked. This option will outstack any contests that have at least one more vote made than the 'Vote For' value defined for that Overvote contest. This will outstack any contest that has a write-in position Qualified marked for a contest that has Qualified Write-ins entered Write-in in EED. This will outstack any ballot that has no marks detected Blank Ballot within any voting target area for the entire ballot. This will outstack any contest that has no marks for any Blank Contest voting target within the contest. This will outstack any ballot where marks are detected for Not Included in any contest not within the reporting set (if one is defined) Reporting Set for that contest. Table 9-1: Standard Voting Outstack Conditions Name Description Duplicated RCV This will outstack any RCV contest where there is a mark Candidate for a candidate in more than one ranking. This will outstack any RCV contest where there are multi- Overvoted Rank- ple marks detected within the same ranking for multiple ing candidates. Unvoted RCV This will outstack any RCV contest where no marks were Contest detected for any rank or choice. Table 9-2: Rank Choice Voting Outstack Conditions 6/18/2024 371 Version: 5.19::4 Chapter 9 - Adjudication Name Description Inconsistent RCV This will outstack any RCV contest where a candidate is Ordering ranked both above and below another candidate. This will outstack any RCV contest where there is a ranking Unused Ranking at the end that is not used. This will outstack any RCV contest where a ranking was Skipped Ranking skipped (and has subsequent rankings made). Table 9-2: Rank Choice Voting Outstack Conditions 6. From the Write-in Rejection Reasons screen (see Figure9-19), the Administrator can: a. Delete rejection reasons that are not desired by clicking on the Recycle Bin from the right. b. Enter any additional/alternate rejection reasons in the Add New Reason field and then click the Add button to add them. These rejection reasons will be added to the profile and used for any Adjudication Sessions initiated from this profile. Figure 9-17: Adjudication - Write-in Rejection Reasons Screen 7. Click Next after the rejection reasons have been removed and/or added as necessary. 6/18/2024 372 Version: 5.19::4 Chapter 9 - Adjudication 8. From the Other Options screen (see Figure9-18), select the other options for the behavior of the Adjudication session, including: a. Require Write-in resolution: When selected, Adjudicators will need to either resolve each write-in vote detected to a Qualified Write-in Candidate or Named Candidate. If not selected, then Adjudicators will be allowed to leave write-ins unresolved. • Write-in resolution not required with overvote: When selected, write-in resolution is not required when the write-in is part of an overvote. b. Allow adjudication for highlighted contests only: When selected, adjudication is only allowed on contests that meet at least one of the defined outstack/filtering criteria. c. Show last adjudication change: When selected, this option will display the most recent set of adjudication overlays when Administrators enter the Review Ballot screen. d. Batch Processing Mode: This setting determines the behavior of the ballot/batch delivery and includes the following options: • Single User Per Batch: Each batch is assigned to a single user, and the user adjudicates ballots for the entire batch. • Multiple Users Per Batch: Ballots are delivered to the next available user as they become available for adjudication. 6/18/2024 373 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-18: Adjudication - Other Options 9. After selecting the desired options, click Next. 10. The final screen of the Adjudication Profile creation wizard is the Summary screen. From this screen, the user is presented with a summary of all the selections they've made during the profile creation. The Administrator can click the Previous button to return to the previous screen(s) of the wizard and make any changes, or they can click Save to save the profile. See Figure9-19. 6/18/2024 374 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-19: Adjudication Profile - Save Profile 11. A Success dialog will display at the top of the screen, as shown in Figure9- 20. Figure 9-20: Adjudication - Success Dialog NOTE: Profile selections can be edited through the Adjudication Profile screen as needed. 9.5 Starting an Adjudication Session When Administrators are ready to adjudicate ballots for an election, they can start an adjudication session using the profile they configured before the election (or without a profile). To start an Adjudication session: 6/18/2024 375 Version: 5.19::4 Chapter 9 - Adjudication 1. From the main Adjudication screen, the Adjudication Administrator (or Technical Support User) must click on the Election Events option (see Figure9-21). Figure 9-21: Adjudication - Click Election Events 2. The Elections that the Administrator has available will display. Click Create Adjudication Session (see Figure9-22). Figure 9-22: Adjudication - Election Events - Create Adjudication Session NOTE: If an Election does not display here, verify that the Election is assigned to the Administrator and that Adjudication is enabled in RTR. 3. The Adjudication wizard will display. To load the profile created pre- election, click the Load Profile button at the top right (see Figure9-23). 6/18/2024 376 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-23: Adjudication - New Session - Click Load Profile 4. The list of available Adjudication profiles will display. The Administrator should select the profile they wish to use and then click the Load Profile button (see Figure9-24). 6/18/2024 377 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-24: Adjudication - Select Profile to Load 5. The Adjudication profile will be loaded, and a green checkmark will display next to each menu item with loaded settings. Enter a Name and Description for the Adjudication session and then click the Next button. See Figure9-25. 6. From the Ballot Filtering & Highlighting section, verify that the correct settings are applied. From here, the Administrator can modify the settings that were loaded in the profile, including: • Filtering settings: Settings options that determine how the ballots will be assessed for filtering/outstack conditions: • Adjudicate all ballots: Selecting this option will present all ballots, regardless of voting conditions met for review by an adjudicator. 6/18/2024 378 Version: 5.19::4 Chapter 9 - Adjudication • Common filtering and highlighting options for all ballots: Selecting this option will allow the Administrator to define one set of outstack criteria for all ballots that are tabulated in the election. • Separate filtering and highlighting options per tabulator type group: Selecting his option will allow the Administrator to define one set of outstack criteria to be used when presenting ballots from central count tabulators and one set of outstack criteria to be used when presenting ballots from Precinct (in-person) tabulators. • Separate Filtering and Highlighting options per counting group**: This option is not available in the Adjudication profile screen because it is election specific. This option can be used if the Administrator wishes to use a separate set of filtering options for groups of ballots based on the counting group of the scanned ballots. • Filtering & Highlighting Options (outstack conditions): The outstack criteria used can be changed prior to starting the session. Outstack criteria can be added or removed as desired. Click the Next button when all options have been set or verified. See Figure9-26. NOTE: Changes made when starting the session will modify the settings for that Adjudication session being started, but the Adjudication profile that was loaded will remain unchanged. Figure 9-25: Adjudication - Basic Data for Loaded Profile 6/18/2024 379 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-26: Adjudication - New Session - Contest Filtering & Highlighting Options 7. From the Write-in Rejection Reasons screen, verify the rejection reasons. Rejection Reasons can be added or removed, as necessary. Click Next. See Figure9-27. 6/18/2024 380 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-27: Adjudication - New Session - Write-in Rejection Reasons NOTE: Changes made when starting the session will modify the settings for that Adjudication session being started, but the Adjudication profile that was loaded will remain unchanged. 8. From the Other Options screen, the Administrator can change the options used for the Adjudication session, if desired. Click Next. See Figure9-28. 6/18/2024 381 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-28: Adjudication - New Session - Other Options NOTE: Changes made when starting the session will modify the settings for that Adjudication session being started, but the Adjudication profile that was loaded will remain unchanged. 9. From the Summary screen the Administrator must review all the options selected and verify that these are the options they wish to use for the adjudication of ballots in the election (see Figure9-29). These options cannot be changed once the session h as started and Adjudication has begun (without starting a new Adjudication session and potentially requiring readjudication of ballots). NOTE: Two options can be changed during the adjudication session: • All Adjudication for highlighted contests only • Show last adjudication change 6/18/2024 382 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-29: Adjudication - New Session - Summary Screen 10. The new adjudication session will start. The status of the Election (from the Election Events screen) will read, ‘In progress’ (see Figure9-30). Figure 9-30: Adjudication - New Session - In Progress 9.6 Using the Adjudication Application Ballots will be delivered to Adjudication Users depending on the settings defined in the session (single user per batch or multiple users per batch) as soon as ballots/batches are scanned and loaded into RTR and subsequently into Adjudication. The subsections below outline procedures Adjudicators and Administrators should follow when entering ballot adjudication. 6/18/2024 383 Version: 5.19::4 Chapter 9 - Adjudication 9.6.1 Entering into Ballot Adjudication as an Administrator When Administrators are ready to enter into ballot adjudication, they should: 1. Log into the Adjudication application. When an Administrator logs into the application each time, the first screen they are presented with is the Dashboard (see Figure9-31). Figure 9-31: Adjudication - Administrator Dashboard 2. To access the ballot Adjudication screen, click on the Election Events menu option from the left (see Figure9-32). The elections that are assigned to the Administrator will display. Figure 9-32: Adjudication - Adjudicate Ballots - Click Election Events 3. Click the Adjudicate button to enter into the Adjudication screen (see Figure9-33). 6/18/2024 384 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-33: Access Adjudication as Administrator 4. If ballots are available (and/or assigned) then they will automatically appear for adjudication (see Figure9-34). Figure 9-34: Ballot Adjudication as Administrator 9.6.2 Entering into Ballot Adjudication as an Adjudicator To enter into ballot adjudication as an Adjudicator: 6/18/2024 385 Version: 5.19::4 Chapter 9 - Adjudication 1. Log into the Adjudication application. When an Adjudicator logs into the application, they will see any Elections that are assigned to them. 2. Click the Adjudicate button (see Figure9-35). Figure 9-35: Access Adjudication as an Adjudicator 3. If ballots are available (and/or assigned), then they will automatically appear for adjudication (see Figure9-36). Figure 9-36: Ballot Adjudication as Adjudicator 6/18/2024 386 Version: 5.19::4 Chapter 9 - Adjudication 9.7 Understanding the Ballot Review Window As ballots become available for adjudication they will display in the center of the screen. 9.7.1 Ballot Information Panel A floating window will display to the left of the ballot containing information about the scanned ballot, see Figure 9-39 on page 388. This window will include different information for the Adjudicator and Administrator: Adjudicators will be presented with the following information (see Figure9-37): • Ballot Type • Precinct • Batch • Record (Ballot position within Batch) Figure 9-37: Floating Overlay Window (Adjudicator View) Administrators will be presented with the following information (see Figure9- 38): • Ballot Type • Precinct • Tabulator • Batch • Record (Ballot position within Batch) • Ballot session type • Batch Status • Adjudication session status 6/18/2024 387 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-38: Floating Overlay Window (Administrator View) Figure 9-39: Understanding the Adjudication Screen 9.7.2 History Panel Clicking on the icon in the top right corner of the Information panel will display the History panel (see Figure9-40). This view shows any ballots that have been adjudicated by the current user for this session. 6/18/2024 388 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-40: Ballot Information Panel - Click History Icon The History panel will then display a list of the ballots that the logged-in user adjudicated (see Figure9-41). The number here indicates the Tabulator, Batch, and Record (i.e. ballot position within batch). Figure 9-41: Adjudication History Panel 9.7.3 Contests Panel To the right of the screen displays the Contests panel (see Figure9-42). This pane displays information about the contests detected for the currently displayed ballot, including the abbreviations for any outstack conditions that were detected. 6/18/2024 389 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-42: Adjudication - Contests Panel By default, the Contests panel displays only highlighted contests (i.e., contests that meet one of the defined filtering/outstack criteria), and an abbreviation for the outstack conditions detected for that contest. The 'Highlighted only' checkbox can be unchecked to view a list of all the contests detected on the displayed ballot card (see Figure9-43). The contests listed will display a checkmark beside them if they have already been viewed or adjudicated by the user. 6/18/2024 390 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-43: Contests Pane - All Contests on Card 9.7.4 Quarantine Panel The Quarantine tab will display the history of the ballot, if it has been quarantined. To view the Quarantine panel, click on the Lock icon from the right of the screen next to the Contests panel (see Figure9-44). Figure 9-44: Click on Quarantine Tab 6/18/2024 391 Version: 5.19::4 Chapter 9 - Adjudication If the ballot was placed under quarantine, then this panel will display the following information (see Figure9-45): • The date and time when the Adjudicator quarantined the ballot • The username of the Adjudicator that quarantined the ballot • The reason that was entered by the Adjudicator for quarantining the ballot Figure 9-45: Quarantine Pane with History 9.7.5 History Panel The History panel will display the history of the ballot, from its original adjudication to any additional times the ballot was adjudicated or reviewed by Administrators. To view the History panel, click on the icon from the top right of the screen (see Figure9-46). 6/18/2024 392 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-46: Click on History Tab The History tab shows the adjudication history of the ballot (see Figure9-47). This includes a list of the actions taken each time a user or administrator adjudicated the ballot. The 'Original' item will display the ballot and its overlays as it was originally tabulated by the ImageCast tabulator. Each time the ballot was adjudicated/reviewed and edited by a user or administrator, a new item is appended to this list, and is numbered according to the order of its occurrence and labeled with the date, time stamp, and username of the user/administrator who adjudicated the ballot. 6/18/2024 393 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-47: History Pane with Adjudications NOTE: The History tab will be empty for most Adjudicators, as they will be the users adjudicating ballots for the first time. 9.7.6 Ballot Navigation Options: Zooming In and Out/Fit to Page From the top left of the screen, there are a set of icons that can be used to navigate the ballot during adjudication (see Figure9-48). 6/18/2024 394 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-48: Adjudication - Ballot Navigation Options The following Table lists these icons and describes their function: Icon Name Description This icon can be used to zoom into the Zoom In ballot image. This icon can be used to zoom out of Zoom Out the ballot image. This icon can be used to fit the entire Fit to Page ballot image to the screen. Table 9-3: Adjudication - Ballot Navigation Icons 6/18/2024 395 Version: 5.19::4 Chapter 9 - Adjudication 9.7.7 Ballot Navigation Options: Overlays and Views From the top right of the screen, next to the Contests panel, there is a stripe of navigation and viewing options (see Figure9-49). These options are described in detail below: Figure 9-49: Adjudication - Ballot Navigation Options Stripe • The Front and Back icons (see Figure9-50) can be used to toggle between the front and back of the ballot card, as seen in Figure9-51 and Figure9-52, respectively. Figure 9-50: Front and Back Icons 6/18/2024 396 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-51: Adjudication - Ballot Navigation - Front Displayed Figure 9-52: Adjudication - Ballot Navigation - Back Displayed • The Side-by-Side page icon (see Figure9-53) can be used to view both sides of the ballot card side-by-side, as seen in Figure9-54. 6/18/2024 397 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-53: Side-by-Side Icon Figure 9-54: Adjudication Ballot Displayed Side-by-Side • The Audit Mark icon (see Figure9-55) can be used to display the Audit Mark, as seen in Figure9-56. Figure 9-55: Audit Mark Icon 6/18/2024 398 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-56: Adjudication - Audit Mark Displayed at Bottom • The Position icons can be used to change the position of the Audit Mark within the Ballot View window (see Figure9-57). By default, the Audit Mark will display at the bottom of the ballot. The Position icons can be used to display the Audit Mark at the top of the ballot, to the right of the ballot, or to the left of the ballot. 6/18/2024 399 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-57: Adjudication - Ballot Navigation - Position Icons • The Overlay icon (see Figure9-58) can be used to show or hide the ballot overlay. The ballot overlay is an overlay of informational elements to indicate to the Adjudicator which contests are being presented for adjudication, why each contest is being presented for adjudication (e.g. any filtering/outstack conditions represented), and how marks are being interpreted. This option can be hidden to allow the Adjudicator a better view of the scanned ballot image, however the overlay must be displayed to complete any adjudication actions. See Figure9-60 and Figure9-59. Figure 9-58: Overlay Icon 6/18/2024 400 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-59: Adjudication Ballot with Overlay On Figure 9-60: Adjudication Ballot with Overlay Hidden 6/18/2024 401 Version: 5.19::4 Chapter 9 - Adjudication 9.7.8 Ballot Navigation Options: Collapsing the Contest, Quarantine and History Panels The Close Panel icon option (see Figure9-61) can be used to collapse the right- hand panel that displays the Contests panel, Quarantine History, and Adjudication History (see Figure9-62). Figure 9-61: Close Panel Icon Figure 9-62: Contests Panel Collapsed To reveal the Contests panel again, click any of the icons for Contests, Quarantine, or History (see Figure9-63). 6/18/2024 402 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-63: Contests, Quarantine, and History Icons 9.8 Adjudicating Ballots 9.8.1 Understanding Ballot Overlays When a ballot is presented for adjudication, a dotted red line will display around the contest that is being presented for adjudication (see Figure9-64). Figure 9-64: Contest Presented for Adjudication with Dotted Red Overlay When the Adjudicator moves their focus (the mouse cursor) to that contest, the dotted red line will display as a solid red line, as seen in Figure9-65. 6/18/2024 403 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-65: Contest Presented for Adjudication with Solid Red Overlay Adjudicators can hover their cursors over the red information icon at the top right to view the Outstack/Filtering conditions detected for that contest (see Figure9- 66). Figure 9-66: Contest Displayed with Hover Over Outstack 6/18/2024 404 Version: 5.19::4 Chapter 9 - Adjudication Ballot images are presented to users with overlays representing whether the vote was originally counted by the tabulator and the confidence percentage of each mark. The system will highlight each choice that contains a detected mark in its area. The following table outlines and elaborates the ballot overlays for different marking scenarios: Mark Detected Green - Counted/Detected mark reflected as a vote (or part of an overvote) by the system. Yellow - Marginal marks are areas Ambiguous Mark where a mark within the dual threshold was detected. These are not counted by the system until/unless a mark is resolved/added to that choice. Mark Removed Red - Mark removed by the Adjudicator. This mark will not be counted by the system or considered as part of an overvote. Table 9-4: Ballot Adjudication Overlays 9.8.2 Toggling the Vote Status To toggle the vote status of a particular choice, the Adjudicator can click on the voting target area for that choice with their mouse. If the choice was previously counted as a vote/mark, clicking on that choice will remove the vote and the overlay will be updated with an ‘X’ over the voting target. See Figure9-67. 6/18/2024 405 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-67: Vote Removed If the choice was previously not counted as a vote/mark, clicking on that choice will add the vote and the overlay will be updated with a green checkmark over the voting target, see Figure9-68. Figure 9-68: Vote Added 6/18/2024 406 Version: 5.19::4 Chapter 9 - Adjudication 9.8.3 Resolving Write-ins To resolve a vote/mark made for a write-in, click on the voting target for the write- in area, as shown in Figure9-69. Figure 9-69: Click on Write-in Target Area A Write-in Resolution window will display to the right of the screen (see Figure9-70). 6/18/2024 407 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-70: Write-in Resolution Screen 1 To Accept the Write-in, click on the Accept Choice drop-down menu. The top of the list will display any qualified write-in names entered for that contest. The Adjudicator can click on the checkbox next to the name they wish to select and then click the Confirm button. To Resolve the Write-in to a qualified write-in candidate, select the checkbox next to the name of the write-in candidate from the top section of the list (see Figure9-71). Figure 9-71: Write-in Accept 6/18/2024 408 Version: 5.19::4 Chapter 9 - Adjudication To Resolve the Write-in to a named candidate on the ballot, select the checkbox next to the name of that candidate (see Figure9-72). Figure 9-72: Write-in Accept to Named Candidate To Reject the Write-in, click on the Reject Choice drop-down menu. The menu will display the list of available rejection reasons. The Adjudicator can click on the checkbox next to the name they wish to select and then click the Confirm button (see Figure9-73). 6/18/2024 409 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-73: Write-in Reject The top of the screen will display a confirmation message confirming the selection made by the Adjudicator. Adjudicators will be required to review both sides of the ballot card if contests that meet outstack/filtering criteria appear on both sides. Once the Adjudicator has completed all adjudication necessary for the ballot, they can: a. Click the Submit and get next button (see Figure9-74) to submit the ballot and get the next ballot. Figure 9-74: Submit and get next button b. Click the arrow at the corner of the Submit and get next button to expand the list of options and then choose from the following (see Figure9-75): • Click Submit and Stop to submit the current ballot and stop adjudicating ballots. • Click Stop to stop adjudicating the current ballot and stop adjudicating ballots. No changes will be saved to the current ballot. 6/18/2024 410 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-75: Submit and get next - drop-down menu A confirmation message will display, prompting the Adjudicator to confirm they wish to save the ballot as adjudicated (see Figure9-76). Figure 9-76: Confirm Ballot Save 9.9 Batch Management To enter the Batch Management screen the Adjudication Administrator or Technical Support user should do the following: 1. Log into the Adjudication application, and then select the Election Events menu item. 2. From the appropriate election, click the Batch Management button (see Figure9-77). The Batch Management screen appears (see Figure9-78), displaying the batches in three columns/statuses: • In Adjudication: Batches for which adjudication has not yet begun, or for which Adjudication has begun and is in progress for at least one ballot in the batch. • Pending Review: Once all ballots in a batch are Adjudicated, the batch will automatically move to the Pending Review column. • Submitted: As batches are reviewed, Administrators will move the batches to the Submitted column. This will make the results of those batches available for Results Reporting and Exports. 6/18/2024 411 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-77: Access Batch Management Figure 9-78: Batch Management Screen 6/18/2024 412 Version: 5.19::4 Chapter 9 - Adjudication 9.9.1 Submitting Batches When Adjudication Administrators are ready to submit the batches, they should follow these steps: 1. Select the checkbox next to any batches they wish to submit from the Pending Review pane. This will enable the button at the top to allow the batch to be submitted. 2. Click the To Submitted button (see Figure9-79). Figure 9-79: Adjudication - Submit Batches 3. A confirmation message will display, as seen in Figure9-80. Click Confirm. Figure 9-80: Submit Batch Confirmation Dialog 4. Once the batches have been submitted, confirmation messages will appear at the top right of the screen (see Figure9-81). 6/18/2024 413 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-81: Submit Batch Success Messages 9.9.2 Sending Batches Back to Review or Adjudication Batches can be sent back to Review to have ballots reviewed/modified by Administrators or sent back to Adjudication to be readjudicated by Adjudicators. To send a batch back for Adjudication or Review: 1. Select the checkbox next to the appropriate batches from either the Review or Submitted column. This will enable the buttons at the top to allow the batch to be reviewed or readjudicated. 2. Click the To Adjudicate button to send the batch for readjudication, or click To Review to send the batch back to review. See Figure9-82. Figure 9-82: Send batch to readjudicate or review 3. A confirmation message will display, as seen in Figure9-83. Click Confirm. Confirmation messages will display at the top right of the screen. 6/18/2024 414 Version: 5.19::4 Chapter 9 - Adjudication Figure 9-83: Change Status Confirmation Dialog 6/18/2024 415 Version: 5.19::4 Chapter 10 - Official Canvass and Post-Election Procedures CHAPTER 10: OFFICIAL CANVASS AND POST- ELECTION PROCEDURES In the post-election period, the jurisdiction will continue to process Absentee/ Mail ballots as well as Early Voting, Provisional and any exception ballots. This process involves: 1. Remaking of damaged and other ballots unreadable by the scanner. 2. Complete scanning and tabulation of all ballots as required. 3. Load results, images, and log files from all precinct tabulators. 4. Complete the adjudication of all ballots with outstack conditions. Ballot adjudication may be done in parallel with scanning on ICC and loading of results from precinct tabulators in RTR. 5. The Adjudication Administrator should continue t submit all adjudicated batches. • Provisional Ballots should be scanned and processed. ® • Scan the remade ballots on appropriate ImageCast Central tabulators. • Resetting result files to allow for adjudication for all results imported on election night with Skip Adjudication option selected: • Display a list of loaded results by clicking on the Result Files option in the Activities Navigation Panel (General group). • In the Result Files main activity screen omit the search criteria and then click on the Search button to list all result files. • Use the Sort functionality to identify result files that are in the “Skipped Adjudication” status. • Select all result files in the “Skipped Adjudication” status and then click on the Reject button - this will change the status of those result files from “Published” to “Rejected” state. • Then, select those same result files and click Reset - this action will change the state of those result files from “Rejected” to “Initial”. • Finally, click Allow Adjudication for all those result files that will result in their adjudication state being transformed from “Skipped” to “Pending Adjudication”. • Complete adjudication for ballots scanned and rescanned as described in this section. • Validate and publish all remaining results into RTR. Run the Statement of Votes Cast report in the RTR. • Back up election project data and results on the EMS Server. 6/18/2024 416 Version: 5.19::4 Chapter 10 - Official Canvass and Post-Election Procedures • Perform post-election system back up. 10.1 Election Observer Panel During the various phases of the election setup process, ranging from: • Central Count equipment programming and configuration • Central Count equipment logic and accuracy testing • Tabulation and ballot marking device programming and configuration • Tabulation and ballot marking device logic and accuracy testing An Election observer panel may be present for activities. This panel may include: • Representatives from qualified political parties • Representatives from legitimate citizens or media organizations The county elections officials may limit the number of observers, as needed. 10.2 Canvassing Precinct Returns Counties should canvass their ballots returned, by precinct. In the canvass of precinct returns, counties should reconcile the following: • Ballots tabulated in the voting system against • Ballots spoiled, damaged, or duplicated & • Ballots issued in the poll book / roster Some helpful precinct canvass reports: Precinct Canvass Report To run the precinct canvass report: 1. Open the RTR Application. 2. Log into the Election Project. 3. From the left navigation pane, expand the Reports submenu. 6/18/2024 417 Version: 5.19::4 Chapter 10 - Official Canvass and Post-Election Procedures 4. Select the Results Reporting option, see Figure10-1. Figure 10-1: Reports submenu - Results Reporting option 5. From the Report Group drop-down menu, select Basic. 6. From the Report Name drop-down menu, select Canvass. 7. Select the Output Type (Excel or HTML). 8. Click Create Report. See Figure10-2. Figure 10-2: Results Reporting Screen - Create Report 6/18/2024 418 Version: 5.19::4 Chapter 10 - Official Canvass and Post-Election Procedures 9. The report will generate in a new window, see Figure10-3. Figure 10-3: Precinct Canvass Report 10.3 Canvassing Absentee Ballots Counties should canvass their ballots returned, by precinct. In the canvass of precinct returns, counties should reconcile the following: • Ballots tabulated in the voting system against • Ballots spoiled, damaged, or duplicated & • Ballots issued in the poll book / roster Some helpful precinct canvass reports: Precinct Canvass Report To run the precinct canvass report: 1. Open the RTR Application. 2. Log into the Election Project. 3. From the left navigation pane, expand the Reports submenu. 4. Select the Results Reporting option. 6/18/2024 419 Version: 5.19::4 Chapter 10 - Official Canvass and Post-Election Procedures Figure 10-4: Reports submenu - Results Reporting option 5. From the Report Group drop-down menu, select Basic. 6. From the Report Name drop-down menu, select Canvass. 7. Select the Output Type (Excel or HTML). 8. Click Create Report. See Figure10-5. Figure 10-5: Results Reporting Screen 6/18/2024 420 Version: 5.19::4 Chapter 10 - Official Canvass and Post-Election Procedures 9. The report will generate in a new window. See Figure10-6. Figure 10-6: Precinct Canvass Report 10.4 Canvassing Provisional Ballots Provisional ballots will be handled according to the county’s business procedure. Counties may decide to tabulate their provisional ballots in a selected batch or counting group. These totals for these batches or counting group(s) can be reconciled against the total number of provisional ballots verified as valid ballots. 10.5 Canvassing Write-in Votes Write-in Votes will be tallied into the following categories: • Accepted – resolved to a qualified write-in candidate • Accepted As-Is – if the write-in is part of an overvote condition • Rejected The jurisdiction can produce reports detailing the total number(s) of write-ins tallied. 6/18/2024 421 Version: 5.19::4 Chapter 10 - Official Canvass and Post-Election Procedures 10.6 1% Manual Recount Procedures In order to prepare for the 1% manual recount, ballots scanned centrally should be prepared in batches of the same or similar size. Additional batches of ballots can be added to the same ImageCast Central batch. The recommended number of ballots to feed into the scanner’s input tray at a given time is: • Canon DR-G1130: apx. 100 ballots • Canon DR-G2140: apx. 100 ballots • Interscan HiPro: apx. 100 ballots loaded into each input tray 1. Batch labels/wrapper sheets to track: a. Date scanned b. Tabulator number c. Operator d. Batch number e. Total ballots scanned in batch 2. Optional: Batch logs to track: a. Date Scanned b. Tabulator number c. Operator d. Batch number A robust batch management procedure will facilitate the easy location of ballots during the 1% manual recount. Conducting the recount County election officials will draw randomly: a. Precincts And/or b. Batches Then, county officials should locate and isolate ballots to be recounted, and manually tally those batches, in accordance with jurisdictional procedures. During the recount, it is important for officials to accounting for digital adjudication activities. This can be done via the Adjudication Activity Log, and the AuditMark. To compare the results of the manual tally against the identified ballots, counties may use the Cast Vote Record export, or the Election Summary report, filtered by batch or precinct. 6/18/2024 422 Version: 5.19::4 Chapter 10 - Official Canvass and Post-Election Procedures 10.7 Post-Election Logic and Accuracy Testing Although not required by California law, this Post-Election L&A can be used to verify that the tabulators logic and the ability to tally ballots accurately has not been compromised since the Pre-Election L&A. The Post-Election L&A can be executed following the instructions in section. 10.8 Final Reporting of Official Canvass When jurisdictions are ready to complete their official canvass reporting, they should verify the following: • All CF/SD Cards from tabulators have been completely loaded and adjudicated (if applicable) • Results • Images • Logs • All VBM (and other central count) ballots have been tabulated and adjudicated • All adjudicated batches have been reviewed and submitted • All results files / batches have been validated & published. Counties may find the following reports useful: • Statement of Votes Cast (broken down by District or Precinct) • Precinct Canvass • District Canvass • District Total Canvass • Cast Vote Record export NOTE: As a best practice, CVR data that is being released for public inspection should follow state and local laws to preserve voter secrecy. Customers should consult their legal advisors for guidance on how best to ensure such protections are applied, particularly if simultaneously releasing any record (ie. video) that could reveal a voter’s identity in the order in which they cast their ballot 6/18/2024 423 Version: 5.19::4 Chapter 10 - Official Canvass and Post-Election Procedures 10.9 Backup and Retention of Election Material 10.9.1 General Procedures Upon the certification of the election results, the California Elections Code applies to the handling, security and disposal of elections materials. The retention period for related election materials is six months for all non-federal elections. The federal election retention period is 22 months. Retention periods may be extended in the event of a court challenge. 10.9.2 Security of Materials Following Ballot Tally • Either on Election night during vote tally, or following vote tally, all of the event log, ballot images and summary totals from each cartridge used in the election shall be backed up to the tabulation database. • The local Election Official shall provide for retention and storage of the database containing the cartridge information and of any other data processing materials related to the vote tally in accordance with statutory retention requirements. • After vote tally, all of these materials shall be placed in locked storage in a secure location, and shall remain there until the expiration of the period for challenging elections and for as long as required by law, unless a court orders their release. • During the period of storage, the local Election Official or the Secretary of State may order the release of the materials for purposes of a manual recount or for election verification. After this process, they shall be returned to storage. 6/18/2024 424 Version: 5.19::4 Chapter 11 - Recount Procedures CHAPTER 11: RECOUNT PROCEDURES 11.1 Request for a Recount A request for a Recount and the conduct of the Recount shall be made in accordance with the California Elections Code Division 15, Chapter 9, Articles 1 through 5, and California Administrative Code Title 2, Division 7, Chapter 8.1. 11.2 Conducting an Electronic Recount 11.2.1 Creating Recount Election Projects 1. From the live election project, create a duplicate copy to be used for the recount by navigating to the Election Project menu in the EMS Election Event Designer client application. 2. Click Save As. Ensure that your duplicate copy is given a unique name by including the word 'Recount' or something similar in the title for clarity. 3. Close the live election project by clicking Election Project in the top toolbar, and then select Close Project. 4. Open the duplicated copy of the original project from the Election Project top toolbar by selecting Open Project, using the same credentials used in the original project. 5. Once you have opened your Election Project, navigate to the Settings menu item on the top toolbar and click Election Event Properties. Roll the election project back to the 'Ballots Generated' stage by selecting the Ballots Generated option from the ‘Election Project Status’ field. 6. If required, create or modify your Device Configuration settings for the tabulator(s) to be used in the recount. Note that you must configure your settings to sort or return overvoted and undervoted ballots so that they can be forwarded to the Manual Recount Election Officials. 7. In the RTR application, select Settings from the top menu, then select Enable/Disable Contests and Choices. You may choose to disable any contests that are not a target of the recount. Alternatively, all contests can be left enabled, and the results reports may be filtered to only report the results of the contest that is the target of the recount. 6/18/2024 425 Version: 5.19::4 Chapter 11 - Recount Procedures 11.2.2 Recounting the Ballots Using the same election files from the copied project, program the Compact Flash memory card(s) and iButton Security Key(s) for the tabulator(s) to be used in your recount, and scan the ballots to be recounted through the tabulator(s). Ballots containing predetermined outstack criteria should be sent through the Adjudication process as normal. 11.2.3 Consolidating Recounted Results 1. When all scanning is complete, load the results into the RTR application using Automatic Results Loading or by loading results from Directory or Removable Media Management. 2. Adjudicate the contests following the applicable criteria determined by your jurisdiction for recount elections. 3. When all results have been loaded and adjudicated, validate and publish the results. 4. Generate results reports as needed. NOTE: If your jurisdiction chooses not to disable contests prior to results reporting or ballot tabulation, ensure to filter results reports by the contests that are the target of the recount, prior to generating any results reports. 6/18/2024 426 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity CHAPTER 12: EMS ADMINISTRATOR'S ROLE IN MANAGING SYSTEM SECURITY AND INTEGRITY It is important to state that appropriate processes must be defined and followed by all business stakeholders within the system, including election staff members of the jurisdiction and Dominion Voting as the vendor, in order to ensure the ® system’s proper security and protection. To this end, Democracy Suite provides the enabling techniques to allow jurisdictions to follow best security practices and ® maintain compliance with local law. The Democracy Suite Threat Register is outlined in appendix G“Threat Register”. 12.1 Physical Security of System and Components Election Event Designer has the ability to perform the following logical input activities: • Restore the election project from the previously-defined election project backup file, packed in the compressed ZIP archive. • Import election definition data from third party entities. • Import recorded dynamic audio files produced by the EMS Audio Studio client application from the EMS workstation. • Import recorded static audio files in the form of SPX/OGG speech-optimized audio files. • Import political party symbols/logos. • Import templates (contest, choice, instructions) for ballot styling in Rich Text Format. The templates are defined as XML files with a .tco file extension. ® • Import ImageCast Central Device Configuration Files. ® ® • ImageCast Evolution and ImageCast Precinct 2 Machine Behavioral Settings. • Import EMS system permission rule sets in XML file format. Election Event Designer (EED) provides the following logical output interfaces: • Ballot images in PDF print-ready format (PDF 1X-a) for use by the ® ImageCast devices. • Audio files in SPX format for ICX. • Audio files in SPX/OGG format and ballot images in PNG format for ® ® ImageCast Evolution and ImageCast Precinct 2 functionality. 6/18/2024 427 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity • Election definition files in a proprietary binary file format to be used by the ® ImageCast Central tabulators. • Credential authentication data used to program iButton Security Keys to be ® used by the ImageCast tabulators. • Device Configuration Files in proprietary binary format to be used by the ® ImageCast Central tabulators. • Machine Behavior Settings files in XML format to be used by the ® ImageCast Evolution tabulators. • A variety of system level reports in XML or PDF format to be used by human or electronic stakeholders. • Audio library definition files in XML format, which define the content to be recorded using the EMS Audio Studio client application. • A ballot on demand definition file which maps polling subdivisions to ballot IDs and allows users to perform polling place ballot-on-demand printing. EED also exposes/provides the following logical input/output interfaces: • The EMS Data Layer Transactions (serialized binary data) toward the EMS Database Server. • The EMS Data Layer Transactions (serialized binary data) toward the EMS Application Server for optional mixed local intranet and remote Internet configuration. The EMS Database Server exposes/provides the following logical input/output interfaces: • The Microsoft SQL Database Engine (serialized binary data) for operation in Election Event Designer and Results Tally & Reporting. • The Microsoft SQL Database Engine (serialized binary data) for use in the EMS Application Server for optional mixed local intranet and remote Internet configuration. The EMS Application Server exposes the following logical input/output interfaces: • The serialized binary communication channel for use in the remote Election Event Designer and Results Tally & Reporting client applications. • The serialized binary communication channel for operation in the EMS Database Server. Results Tally & Reporting (RTR) allows for the following logical inputs: • User input. ® • Result files in proprietary binary file format collected from the ImageCast Central tabulators. 6/18/2024 428 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity ® • Result files in XML format collected from the ImageCast Evolution tabulators. ® • Imported ImageCast ballot counters. ® • Imported scanned ballot images from the ImageCast Evolution, and Central ballot counters. • Imported XSLT (XML Stylesheet Transformation Templates) used to define election result reports. Results Tally & Reporting provides the following logical output interfaces: • Result reports in XML, PDF, HTML or Excel format used by EMS human and electronic stake-holders The type of exported data depends on the XSLT transformations. 12.1.1 Essential and Non-Essential Services and Ports To further secure election servers, place a self-adhesive, tape-style tamper evident seal over any unused USB, Ethernet, or other port on the server and client ® workstations for EMS and ImageCast installations. 12.1.2 Anti-Virus Protection Dominion Voting requires the installation of Windows Defender anti-virus protection for server computers.These virus and spyware prevention/detection packages must be present on all server and client machines of the Democracy ® Suite EMS environment. These virus prevention/detection packages must have heuristic virus checking activated, and should be only temporarily disabled when restoring, creating, or configuring an Election Project on a client workstation. Any resident prevention/detection features must be active. The virus prevention/ detection packages must be updated to the latest version of the application and virus/spyware definition databases every week. Such updates will have to be introduced via a mobile storage device, as no external access to the network is permitted. These virus/spyware prevention/detection packages must be automatically run at set times every 24 hours. The set times should be chosen to minimize operational impact (during the night). Scans must be run on all attached storage devices and logs from these scans must be inspected and archived. If a virus’ or spyware’s binaries are detected, immediate action must be taken to isolate and remove it, in accordance with the virus prevention/detection package supplier’s recommendations. This may simply involve quarantining and deleting the offending program, or in some circumstances a special removal tool may have to be used. If virus/spyware infection is observed, additional measures must be taken including, but not limited to: 6/18/2024 429 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity • Temporarily removing all machines from the network. • Turning off System Restore and running both virus scanners. • Formatting the hard drives of all infected machines and re-installing the operating environment from a clean installation source. Some malware overwrites the boot record of a computer is not removed, even with reformatting. One day prior to Election Day, both virus prevention/detection packages must be manually run or the scheduled scan manually verified. On Election Day/Night, the automatic running of the virus prevention/detection packages must be suspended to ensure that there is no potential conflict or performance impact while results are processing. If necessary, run a manual scan so that within 24 hours of the tally, it can be confirmed that the anti-virus software showed no infection on the computer during Election Day and Election Night operations. ® Installation procedures are listed in Dominion Voting Systems Democracy Suite Installation Procedures. 12.1.3 Procedures for Verifying, Checking, and Installing Essential Updates and Changes Unless authorized or required by the Secretary of State, no software or operating ® system updates should be installed on a Democracy Suite installation. Installing updates of any kind will violate the certified configuration of the voting system. If an update is authorized by the California Secretary of State, Dominion Voting Systems will then provide specific instructions on how to successfully perform a software update that conforms to the certification requirements and regulations set forth by the State of California. 12.1.4 Audit Records for Changes Windows event logs show the antivirus updates as they are installed. 12.2 Administrative Control of the Backup and Restore of an Election Project 12.2.1 Backing Up an Election Project To do a backup of an election project, do the following: 1. Open EED by double-clicking the EED shortcut on the desktop. Select Election Project and then click on Open Project. In the ‘Open Project’ select the project form the list and then click OK. 2. Log into the project by entering the Administrator username and password. 6/18/2024 430 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity 3. Once the election project is open in EED, click Election Project and then select the Create Project Package option from the drop down menu. 4. The dialog window will open where you will choose the full back up (which appears as the second option in the dialog). Click on the Continue button. 5. Once the procedure is complete, the Information dialog window will appear notifying the user that the back up was successfully completed. 6. The project package will be saved at the following location on the NAS: D:\NAS\[NAME OF ELECTION PROJECT]\Project Package Copy the project backup ZIP file to the safe location. A project package backup can also be created during the Restore database process, if the project being restored already exists on the EMS NAS: • To perform a backup of an election project, select the project package in the Restore dialog window. The package will load (this may take some time) and you will then be able to see information concerning the package contents displayed in the dialog window. NOTE: If the election project does not exist on the EMS server, you will be presented with a message notifying you that the project does not exist on the EMS Database server. If you wish to continue, click OK. • On the next screen the Warning dialog will appear. • To create a backup file from this point, select the Create Election Project Package File check box. • Click Browse and navigate to the location on the server where you want to save the election project package. Put the backup into a folder with a descriptive, recognizable name. • Once complete, select the Create option to create the election project package file. • When the process has successfully completed, click OK to proceed. • Click on the OK button to continue. • To initiate the restore process, click the Restore button. • After the restore process has successfully completed, click OK. A minimum of four complete project package backups should be made during a typical election cycle: 1. Initial - the project package as supplied by Dominion Voting or produced by the jurisdiction. The election project has been fully completed, and is in the “Ready for Elections” state. 6/18/2024 431 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity 2. Logic & Accuracy test results - a backup of the election project after the L&A test has been successfully completed. This backup contains all of the scanned results, images, and logs of the L&A test as well as any of the pre-defined results reports that were produced. 3. Semi-Official canvass (Election night) results - a backup of the election project at the end of Election night tabulation and reporting has been successfully completed. This backup contains all of the scanned results, images, reports and logs of the Semi-Official results reporting. 4. Official canvass (Final) results - a backup of the election project at the end of the canvass period with all ballots tabulated. This backup contains all of the scanned results, images, reports and logs for the entire election. 12.2.2 Restoring an Election Project To restore an EMS database: 1. Expand the Administration menu and click Restore EMS Database. The Restore Election Project Package screen appears. 2. There are two options of restoring project: Local Path on the Server and Local Path on the Client. 3. Next, select whether the backup you are restoring is on the Client or the Server and browse to the corresponding backup zip file, and then select Open. 4. After you have selected the backup zip file, you will see that project’s information populate the two windows featured in the Restore Election Project Package combo box. If you want to continue with the restoration, select OK. 5. The next screen warns you that if you are restoring a current project, all associated files will be deleted from the Database and NAS Servers. If you would like to proceed to create an Election Project Package File, select Browse to choose a file location, and then select Create to create the Election Project Package file. 6. Select OK to acknowledge the warning, and to proceed with the restoring process. 7. To initiate the restore process, click the Restore button. 8. After the restore process has successfully completed, click OK. 9. Open the election project. NOTE: If you restore your election project package on an EMS workstation with a hard drive sector size that differs from the workstation that the project was created on, you will receive an Operation Cancellation error if you attempt to create a backup of your project. In order to circumvent this error, delete the old backup file (.bak) from the \NAS\<PROJECT NAME>\DB\Backup folder. 6/18/2024 432 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity 12.2.3 Encrypting an Election Project Counties may need to encrypt a project after its creation. These steps should be followed to encrypt a project: 1. Log into the election project in the Election Event Designer (EED) application. 2. From the main menu toolbar, select Settings > Project Parameters. The Project Settings - Project Parameters dialog appears. 3. Select the Security tab, and then select one or both of the following options (see Figure12-1): • Encrypt sensitive data: To encrypt sensitive data, select Encrypt from this section of the screen. • Encrypt database file: To encrypt the database file, select Encrypt from this section of the screen. Figure 12-1: Project Parameters - Security Tab 4. Click OK. 6/18/2024 433 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity 12.2.4 Importing an Encryption Certificate If you attempt to log into an encrypted project in EED without importing the corresponding encryption certificate that was used to encrypt the project, a warning will display, as seen in Figure12-2. Figure 12-2: Error message dialog To import an encryption certificate: 1. From to the top menu in EED, select Administration, and then select Import Encryption Certificate. See Figure12-3. Figure 12-3: Import Encryption Certificate option 2. Select the ellipsis (‘...’) button to browse to the location of the saved encryption certificate. See Figure12-4. Figure 12-4: Import Project Database Encryption Certificate dialog 6/18/2024 434 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity 3. Browse to the location of the certificate, select the certificate, and then click Open. See Figure12-5. Figure 12-5: Opening Encryption Certificate File 4. Enter the password for the certificate and then click OK. See Figure12-6. NOTE: If Dominion Voting Systems is performing the setup of your election project, this password should be provided to you from your customer relations manager/technical service representative. Figure 12-6: Import Project Database Encryption Certificate - Password 5. An informational message will display once the certificate has been successfully imported, as seen in Figure12-7. Click OK. Figure 12-7: Informational dialog The project will now be accessible in the EED application. 6/18/2024 435 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity 12.2.5 Exporting Encryption Certificates Once projects are encrypted, the encryption certificate(s) need to be provided, as well as the project package to restore the project on other servers. Follow these steps to export the encryption certificates: 1. From the Start menu on the EMS Server, open the application named EMS Application Server Manager (see Figure12-8). Figure 12-8: EMS Application Server Manager 2. Select the Application tab. 3. To export the Sensitive data encryption certificate: a. Under Certificate Export, select the Sensitive data encryption certificate radio button. b. From the corresponding drop-down menu, select the Server Certificate to export the certificate for the current server. 6/18/2024 436 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity c. Click Export Certificate. See Figure12-9. The Export project database encryption certificate dialog displays. Figure 12-9: Exporting the Sensitive data encryption certificate NOTE: You will see other certificates here that have been imported for projects that were encrypted on other servers. To export the certificate for any projects encrypted on this server (the one you are currently accessing/logged into) select the Server Certificate. Select the other certificates if you need to export the certificates for those projects. d. Input a password and confirm the password in the fields provided. e. Click OK (see Figure12-10). A Save As dialog appears. Figure 12-10: Export project database encryption certificate dialog f. Browse to the location where you wish to save the file and click Save. A confirmation dialog appears. g. Click OK. 4. To export the Database file encryption certificate repeat steps 1 and 2, and then proceed with the following steps (see Figure12-11 for reference): a. Under Certificate Export, select the Database file encryption certificate radio button. 6/18/2024 437 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity b. From the corresponding drop-down menu, select the project for which you need to encrypt the certificate. Figure 12-11: Exporting the Database file encryption certificate c. Click Export Certificate. The Export project database encryption certificate dialog displays. d. Input a password and confirm the password in the fields provided. e. Click OK. A Save As dialog appears. f. Browse to the location where you wish to save the file and click Save. A confirmation dialog appears. g. Click OK. 12.2.6 Setting up Project for Additional Audio Languages If the Election Project is intended to support audio for languages other then those automatically provided for by EMS system, the audio folders for such languages need to be created manually on the EMS server by the Administrator. On the EMS server, navigate to D:\NAS\Common\Audio folder. Once inside the Audio folder, right-click and select to create New Folder. Name the language folder with the name that exactly matches (case sensitive) name used to define that same language in EED when creating languages. This folder should contain audio files for all static files in that language. Repeat the process until all desired languages have been added. 6/18/2024 438 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity 12.2.7 Creation of RTR User in Election Event Designer In order to open an election project in Results Tally & Reporting, you need to create and activate an RTR user. 1. Open your election project in Election Event Designer. Expand the Administration menu and click the Application Users menu item. The Administration - Application User context sensitive screen opens. Click Search to list all available users. Next, perform the following: 2. In the Application drop down menu, select EMS RTR. 3. Click Create New. The Application User dialog appears. Enter an appropriate username. 4. From the Role drop down menu, select the RTR Administrator role. 5. Select Manually create password. Enter a case sensitive password in the enabled fields. NOTE: Default password type – Minimum length is 8 characters which must include at least one number and one letter from the alphabet. Strong password type – Minimum length should be 10 characters which must include at least one number, one special character and one letter from the alphabet. Weak password type – minimum six characters. NOTE: There is an option to add the relevant contact information on the right side of the dialog. 6. Click Save and Close to close the dialog and return to the Administration - Application User screen. 7. Open the newly created RTR user. 8. Change ‘Status’ from Initial to Active. Click Save and Close again. 12.2.8 Initializing Reporting Services On the EMS Server: 1. Open the EMS Application Server Manager by clicking Start > All Programs > DVS > Application Server Manager, and then selecting Application Server Manager. 2. Click Yes to accept the UAC prompt and continue. 3. On the Database Settings tab, click Test to verify that the connection to the database was correctly established. 4. Click the Reporting Service Settings tab. 6/18/2024 439 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity 5. Click Initialize Service and wait for the “SQL Reporting Service initialized!” message in the bottom text box. 6. Press Test and wait for the “Connection successful! Folder ‘EMS Application Server Reports’ already exists!” message to appear. 7. Click Save Settings, and then click Close. 12.3 Disabling and Enabling Adjudication in EMS RTR 1. Expand the Settings menu and click on the Project Properties menu item. The Project Settings dialog appears. 2. Uncheck the Enable Adjudication option. Unchecking this item will ensure that the Adjudication process is not included in the workflow when managing result files. 3. Click Apply, and then click OK to close. 12.4 Purging Election Results 12.4.1 Purging Election Results from RTR The purpose of purging election results from RTR is to clear results from a previous election before starting a new election. 1. In the Main Menu, click on Actions, Results and then click on the Purge Results option.The Confirm Purging dialog window will open. 2. In the Confirm Purging window, enter the text sequence that appears on the screen and click on the OK button to confirm purging. 12.5 Security Procedures for Central Processing The official environment of the central count location is under the control of the jurisdiction, which determines its own physical security requirements for their central count facility. The jurisdiction is also responsible for handling and storing ballots both before and after they have been scanned. The following is a suggested high-level ballot handling procedure for central processing: Ballot boxes are typically stored on racks until they have been scanned and should remain on these racks until this point. Before the scanning process, a ballot handler is assigned to a specific scanner and is responsible for retrieving boxes of ballots from the racks for this scanner. Once the scanner count records are compared and matched to the poll record, and every total has been balanced, the ballots are ready to be re-boxed. A post- scanning ballot handler reclaims the scanned ballots from the scanning tables and 6/18/2024 440 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity packs them into boxes. Ballots should remain in the order they have been scanned in order to facilitate easier tracking, if needed, in the future. The poll record is also repacked. Before the box is sealed, the handler obtains the ‘follower’ from the system. This document details the scanning and accounting process. The ‘follower’ is also placed inside the ballot box. The box is sealed with a clear, tamperproof and traceable envelope. Each box is placed in storage at a pre-determined location for traceability. 12.6 Security Procedures for Polling Places 12.6.1 Polling Place Physical Security ® The following physical security mechanisms are integrated within the ImageCast devices: • Tamper-proof screws are used for all external fixtures. • Each device door is secured with an appropriate locking mechanism (hasp- type for either physical locks or tamper seals and security screws). • The ballot box has its own locks for each of the ballot box compartments. As per jurisdiction’s regulations, poll workers should perform an orderly shut down of the tabulator to protect the units in the event of vandalism or civil disobedience. If the poll worker determines that a shutdown is required, given the severity of the disruption in the polling place, the following actions should be taken: 1. Document the public counter 2. Power down the tabulator 3. Cover the machines with available covers or move them to a safe place 4. Remove laptops or other computing devices out of the polling place 12.7 Audit Trails 12.7.1 ImageCast® Evolution Audit Trail Files This section describes the context and purpose of voting system audits and related, specific functionality requirements. Election audit trails provide the supporting documentation for verifying the accuracy of reported election results. They present a concrete archival record of all system activity that is related to the vote tally. As such, election audit trails are essential records that provide public confidence in the accuracy of the tally, information in the event of a recount, and evidence in the event of criminal or civil litigation. 6/18/2024 441 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity ® 12.7.1.1 ImageCast Evolution Audit Log File ® Every action, event, and operation that occurs on an ImageCast Evolution will be permanently logged to the audit log file that exists on both memory cards. This file is encrypted and digitally signed to protect its integrity. Authorized users can use the LCD touchscreen to print this Audit Log report on ® the ImageCast Evolution ’s internal printer. This LCD on-board Audit Log report only reports on a maximum of forty audit events (i.e. the last forty audit events to have occurred. If users use the LCD screen to request a report of more than forty audit events, the system will still only report the maximum forty audit events). This printing procedure meets the following: • The generation of audit trail records does not interfere with the production of output reports. • The entries can be identified so as to facilitate their recognition, segregation, and retention. • The audit record entries are kept physically secure. 12.7.2 ImageCast® Precinct 2 Audit Trail Files ® 12.7.2.1 ImageCast Precinct 2 Audit Log File Every action, event, and operation that occurs on an ICP2 is be permanently logged to the audit log file that exists on the SD1 card. This file is encrypted and digitally signed to protect its integrity. This file can be uploaded to EMS RTR. 12.7.3 ImageCast® Central Audit Trail Files ® 12.7.3.1 ImageCast Central Audit Log File ® Every action, event, and operation that occurs on the ImageCast Central is permanently logged to an audit file that exists on the host workstation and the host results server, if uploaded to the secondary path. The report.txt is generated to display ICC election reports/ statistics. The slog.txt records all activities and can be found on the local workstation at C:\Projects\Tabulator Name (where the Projects folder is defined as the Primary path during application setup and installation). This printing procedure meets the following: • The generation of audit trail records does not interfere with the production of output reports. • The entries can be identified to facilitate their recognition, segregation, and retention. 6/18/2024 442 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity • The audit record entries are kept physically secure. 12.7.3.2 Audit Mark Images For each ballot that is scanned, interpreted, and accepted into the unit, a corresponding ballot image with Audit Mark is created and stored for auditing purposes. The system uses these images to audit the unit’s interpretation of each individual ballot. ® The ballot image with Audit Mark on ImageCast Evolution consists of two parts: 1. The top part of the image contains a scanned image of the ballot (the voter markings are of particular importance). 2. The bottom portion consists of the AuditMark, a machine-generated analysis summary showing each mark that the unit interpreted for that particular ballot. ® The ballot image with AuditMark on ImageCast Central consists of three parts: • 1st page - Ballot front side • 2nd page - Ballot back side • 3rd page - AuditMark 12.7.3.3 Audit Trail Files ® The Audit trail file on ImageCast Evolution is stored in memory and contains a ® chronological list of all messages generated by the ImageCast software. This includes: • System startup messages (recorded by the Application Loader) • System self-diagnostic test messages (memory test, module initializations) • All administrator operations (messages include the “access key” id number) • Source and disposition of system interrupts resulting in entry into exception handling routines • All messages generated by exception handlers’ notification of system login or access errors, file access errors, and physical violations of security as they occur, and a summary record of these events after processing • Non-critical status messages that are generated by the machine’s data quality monitor or by software and hardware condition monitors • All scanned ballots • All system errors (paper jams, power failures, hardware failures, data errors etc.) 6/18/2024 443 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity To ensure the integrity of the Audit log, all records added to the file are encrypted using AES-128 and the common key value and the entire file is signed using a SHA-256 hash and the tabulator’s unique key value. ® On ImageCast Central, every action, event, and operation that occurs on a ® ImageCast Central is permanently logged to an audit file that exists on the host workstation and the host results server. This file can be found in C:/dvs/Temp/. All audit record entries include a time-and-date stamp. The generation of audit record entries is terminated or altered by program control, or by the intervention of any person. The physical security and integrity of the records are maintained at all times. The Audit Log can be printed using the EMS Results Tally & Reporting system. Dominion recommends that this log, once printed, be kept in a physically secure location for a period of at least 22 months. As per VVSG Vol. 1 requirements, this printing procedure meets the following: • The generation of audit trail records does not interfere with the production of output reports. • The entries can be identified to facilitate their recognition, segregation, and retention. • The audit record entries are kept physically secure. 12.7.4 ImageCast® X Audit Trails ® Every action, event, and operation that occurs on an ImageCast X will be permanently logged to the audit log file that exists on both memory cards. This file is digitally signed to protect its integrity. Authorized users can see the Audit Log report on the screen. Audit Log can be exported onto a USB removable medium. The export procedure meets the following: • The generation of audit trail records does not interfere with the production of output reports. • The entries can be identified so as to facilitate their recognition, segregation, and retention. • The audit record entries are kept physically secure. 12.7.5 EMS Audit Trail File 12.7.5.1 EMS Audit Log From the moment the project is created in EMS to the moment the project becomes deactivated, the EMS system keeps an activity log within the EMS Database. This activity log stores every action performed by any user within the 6/18/2024 444 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity system, and thus functions as a detailed audit log that can be analyzed and printed in the form of an audit report. The audit information cannot be modified or permanently deleted from the EMS client applications. However, the report should be exported for archiving purposes as part of the record retention policy. Keeping in mind that audit logs can contain a significant amount of information, it is the responsibility of the administrative user to regularly archive log information. Doing so will clear the log and create more space for new records. The auditing activity displays this auditing report in EED. The reports found in the Audit Log Report Group are associated with the usernames that have been created within EED (e.g. Admin and Techadvisor). That is to say, the produced reports will log each action that a specific user performed at a certain period of time. These reports show details such as “User Name”, “Report for Time Period”, “Time” and “Action”. The report is generated in simple text format and can be exported into PDF, HTML or MS Excel format. The created report is stored on the NAS and signed using the election project key. Reports are created with the assigned date, and multiple reports can be generated. 12.7.5.2 Unauthorized Access to the Access Control Capabilities of the System EMS application user accounts (including roles, permissions and user credentials) are stored within the EMS Database. Access to this database can only be achieved by using the EED and RTR client applications. No other components of ® Democracy Suite have access to this database repository. Direct access to the database platform (server and underlying database engine) requires special administrative privileges and cannot be performed from any of the client applications. This means that to access the EMS Database directly, the user has to first establish prerequisite infrastructure equipment, bypass physical security measures, pass the Windows Server authentication, and then pass SQL Server authentication. 12.7.5.3 Reports Election Event Designer contains seven groups of reports presenting a variety of application activities. The convenience of the report tool is that it can be easily previewed, formatted, and filtered. Additionally, the user can obtain the custom prepared reports that modifies, deletes, or adds new sets of reports. The report tool contains XSLT, otherwise known as XSL transformations, that converts XML files into HTML, PDF, or XML with the ability to be opened in Excel. The default XSLT is imported into the election project when a new project is created. 12.7.5.4 Create, Preview and Delete Reports The report navigation group consists of the election project, divisioning, election event, tabulation, system report, audit log, and ballot reports groups. The procedure for creating reports is the same for all. To create a report, perform the following steps: 6/18/2024 445 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity 1. Expand the Reports navigation group and select one of the report items. 2. Select the option from the Report Name drop down menu. The drop down menu contains a list of available reports for the selected Reports Group. 3. Select the Transformation Name you can choose between one of the presented options. 4. Click Create Report. 5. The creation of the report will take a few seconds. While the system collects all of the data needed to create the report, the progress bar will appear. The report viewer will open upon completion. 6. Each report spreadsheet contains the election project and report name. XML files can be converted into HTML, PDF or Excel by applying a chosen report transformation. 1. Select the XML report from the list of created reports. 2. Choose the Transformation Name option from the drop down menu. 3. Click Apply to apply the chosen transformed report. To preview the created report, navigate to the Report Group main activity. Select the Report Name and click Search. One or more reports matching your search criteria appears in the main activity screen. Select the reports from the list and click Open. To delete one or more reports, perform the following steps: 1. List the reports. 2. Select the reports. 3. Click Delete to delete them from the NAS repository. 12.7.5.5 How to Download Reports from the NAS Server All created reports are stored on the EMS NAS servers. The created report can be opened and previewed by using the Document Management window. If you wish to print the report, you must first download it from the NAS server and save it to your local drive. 1. Open Document Management and expand the Actions menu. 2. Select the Open Document Management submenu to open the Document Management window. 3. Select the target folders: on one pane select the EMS NAS server, and on the other select where you would like to save the report on your local drive. 4. To navigate to the reports, double-click on the Reports folder. 6/18/2024 446 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity 5. Double-click on the desired Report Group. Depending on the chosen report transformation, the reports will be presented in XML, PDF and Excel format. Additionally, the system will create a SHA file for each report. 6. Drag the report from the EMS NAS server and drop the file to your desired local location. 12.7.5.6 How to View System Level Logs EMS system level logs for the EMS can be found in the Application and Service logs on the computer running the application. To access these logs: 1. Right-click the Computer icon and click Event Viewer. 2. Expand Event Viewer, and Applications and Services Logs select EMS System. NOTE: Additional logs for individual EMS application machine/server components can be found in the program files where the application was installed. For example, to view logs from the Election Event Designer view C:\Program Files\Dominion Voting Systems\Election Event Designer \Log 12.7.5.7 Results Auditing After processing election results, there is a need to inspect the system operation in a more detailed manner. As a result, RTR client application has the ability to produce a detailed audit report on how ballots were marked and how they were interpreted by tabulator devices. In addition, EMS RTR collects and copies all ® relevant ballot scans to be visually inspected. Furthermore, all ImageCast log files are visible through the RTR application. ® For full details on the ImageCast system’s audit functions, please refer to the following user guides: ® • Democracy Suite EMS Election Event Designer User Guide ® • Democracy Suite EMS Results Tally & Reporting User Guide ® 12.7.5.8 ImageCast Adjudication Audit Trail The ImageCast® Adjudication system keeps track of all adjudication actions taken on a ballot, including user name and time of the action, and stores this information in the database. To obtain this information, an Adjudication Administrator can create an Activity Report from the RTR application in PDF format. Additionally, adjudicated ballot images are appended with audit information in ® the same manner that the ImageCast Central appends interpretation ® information (see section 12.7.3 “ImageCast Central Audit Trail Files”). The 6/18/2024 447 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity appended Audit Mark forms a permanent record of adjudication actions taken on a ballot and can be easily inspected at any time by opening the image with a standard image viewer. System-level logs also record information about system operation and errors. This is stored in the Windows Event Log on the EMS server, as well as in each Adjudication workstation. ® To access the ImageCast Adjudication logs: • From the Start Menu, right-click Computer and select Manage. This will open Server Manager on the EMS server, or Computer Management on a workstation. • On the left pane, expand Diagnostics if on the EMS server, or System Tools if on a workstation. • Expand Event Viewer. • Select the “DVS Adjudication” log under Applications and Services Logs. • To ensure all information listed is up to date, select the Refresh button in the Actions pane on the right. • On the center pane, you will see entries logged by Adjudication components. The Source column will identify the exact component (e.g., one of the services, or the client application). 12.7.5.9 Lookup After determining a truly random sample size (usually from amongst the precincts in an election) and elements to review within that sample (paper ballots, ballot images, log files, chain of custody, etc.), the first step when performing an audit is to lookup the list of scanned ballot images and log files based on specific criteria. The generation of audit record entries will not be terminated or altered by program control, or by the intervention of any person. The physical security and integrity of the record are maintained at all times. The user can export audit images for a subset of result files, for a single contest or for all contests. For each export a separate subfolder will be created. Inside the subfolder maximum two subfolders can be created: • published: Folder containing all images belonging to published results. • notpublished: Folder containing all images belonging to non-published results. If no contest was selected the following subfolders will be created inside these folders: • BlankBallot: No contest was marked on the ballot. • Blank: At least one contest did not have any votes on the ballot. 6/18/2024 448 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity • UndervotedNotBlank: At least one contest was undervoted on the ballot. • Overvoted: At least one contest was overvoted on the ballot. • Regular: Each contest was fully voted on the ballot. • Writein: Write-ins were marked on the ballot. ® A similar approach is available for log files produced by the ImageCast filtering can be performed based on tabulator instance. 12.7.5.10 EMS Data Center Physical Security ® The Democracy Suite EMS environment must be physically secured in a locked area with security access controls in place. No access to this area should be permitted to unauthorized personnel. Dominion Voting requires that an access control system is utilized that will automatically log and record each individual’s access to the EMS Data Center environment. Such systems include the use of electronic passes or biometrics to gain entry into the secure area. In addition, if cameras and/or a card-key system are not in use, all personnel must be required to sign in and out when accessing the secure ® Democracy Suite EMS environment area. The access log must include: name, organization, purpose of access, date, time in, time out, and signature. Buildings and rooms within those buildings which contain EMS and ICC installations must be secured. Security for these can include traditional methods such as keys and locks, card-keys, and surveillance cameras. Each jurisdiction and building is different; thus an exhaustive discussion of election system building security is not possible in this Guide. Consult with your jurisdictions law enforcement or other security related agency for assistance in securing the voting system installation. 12.7.5.11 Operational and Maintenance Procedures As with any information and communication technology system, the Democracy ® Suite EMS platform requires some regular operational and maintenance procedures. These procedures ensure the reliability, availability and security of the overall system. These procedures are usually scheduled for off-election periods, either before or after the election event. Some of the operational procedures, however, should be performed regularly (daily) throughout its use. Operational procedures to be performed in regular intervals (daily while the system is in use) are: • Review of the log files for each of the system components (including EMS server components, EMS client components, networking switch equipment, etc.). • Review of the EMS-specific audit log files. 6/18/2024 449 Version: 5.19::4 Chapter 12 - EMS Administrator's Role in Managing System Security and Integrity • Review of the back-up procedures and execution of additional back-up procedures (if needed). • Review of anti-virus and any other security software event logs. 6/18/2024 450 Version: 5.19::4 Chapter 13 - Biennial Hardware Certification and Notification CHAPTER 13: BIENNIAL HARDWARE CERTIFICATION AND NOTIFICATION California Elections Code requires jurisdictions to inspect voting systems, and certify their accuracy on a biennial basis (once every two years). All tabulators, scanners, elections management software, and supplementary equipment must be certified by California’s Secretary of State prior to their use in any election taking place in California. All specialized tally equipment must be certified for use in elections by the Secretary of State prior to use in any election. 13.1 Notification of Equipment For each statewide election, the responsible county Election Official shall cause to be prepared a list, including quantities, of all equipment to be used to tabulate votes during the semi-official and official canvass. Seven days before each statewide election, the Election Official shall certify to the Secretary of State the results of the logic tests as well as the accurate functioning of all ballot tally equipment. This certification shall also affirm the use of the same equipment for the Pre-Election Logic and Accuracy test, and for semi-official and official vote canvasses. In the event of a change to the ballot tally program after certification, an amended certificate shall be submitted no later than the day before the election. In the event any equipment is repaired, altered or replaced following the certification specified in this section, and prior to completion of the official canvass of the vote, an amended certification of Logic and Accuracy testing and a revised list of equipment used must be submitted to the Secretary of State no later than submission official canvass. 6/18/2024 451 Version: 5.19::4 Appendix A - ImageCast® Central 2 Machine Behavior Settings APPENDIX A: IMAGECAST® CENTRAL 2 MACHINE BEHAVIOR SETTINGS The ICC2 uses a default MBS as provided with the EMS release and imported into EED project during the programming of the election project. The settings should not be changed. However, if you require further information about the default ® ® settings in the MBS file, please refer to the Democracy Suite ImageCast Machine Behavior Settings document. 6/18/2024 452 Version: 5.19::4 Appendix B - ImageCast® Evolution and ImageCast® Precinct 2 Machine Behavioral Settings APPENDIX B: IMAGECAST® EVOLUTION AND IMAGECAST® PRECINCT 2 MACHINE BEHAVIORAL SETTINGS ® ® ImageCast Evolution (ICE) and ImageCast Precinct 2 (ICP2) Machine Behavior Settings are configuration files used in conjunction with the ICE and ICP2 to configure the tabulator’s behavior during an election. The Machine Behavior Settings file is imported into the Election Event Designer application for ® configuration and customization, see the Democracy Suite EMS Election Event Designer User Guide for details. Once imported, the file can then be modified by selecting either numerical values or options for each of the tabulator’s functions. ® ® Please refer to the Democracy Suite ImageCast Evolution Machine Behavior ® ® Settings and Democracy Suite ImageCast Precinct 2 Machine Behavior Settings documents for additional details on how to set the values to adhere to the State of California’s election requirements. “B.1Polling Place Tabulators” and “B.2Early Voting Tabulators” below describe the appropriate MBS settings for “Polling Place” and “Early Voting” tabulators. The MBS file structure for the ICE and ICP2 tabulators is divided into the following categories: • Security • Results Files • Standard Voting • Accessible Voting • Touch Voting • Vote Verification • Smart Card • Early Voting • Voter Languages • Image Processing • Write-ins • Thermal Printer • Write-in Report • Provisional/Challenge Voting • Advance Administration 6/18/2024 453 Version: 5.19::4 Appendix B - ImageCast® Evolution and ImageCast® Precinct 2 Machine Behavioral Settings • Results Transfer • Shoe Shine • HW Settings • Intrusion Detection • Voting Rules Each category contains its own set of MBS options that can be configured to adhere to election requirements B.1 Polling Place Tabulators The default MBS file that is provided with the EMS release and imported into the project, is the file that should be used for the polling place (Election Day) ICE and ICP2 tabulators. B.2 Early Voting Tabulators The Early Vote MBS differs from the default MBS (which is provided with the EMS release) in that some of the Thermal Printer Tape settings are changed. Early Voting tabulators are typically programmed for many precincts and if the number of Ballot Types and Precincts programmed on a tabulator is very large, the zero and especially the report tape can be extremely long. To avoid that, some settings are changed in the MBS to shorten the length of the report tape. 6/18/2024 454 Version: 5.19::4 Appendix C - ImageCast® X Configuration Files APPENDIX C: IMAGECAST® X CONFIGURATION FILES ® ImageCast X Machine Configuration File (MCF) is a configuration file used in ® conjunction with the ImageCast X in order to configure the device’s behavior. The Machine Configuration File is imported into the EMS Election Event Designer application for further configuration and customization. Once imported, the file can then be modified by changing values or options for each of the tabulator’s functions. ® The MCF file structure for the ImageCast X tabulators is divided into the following categories: • Main Settings • Admin settings • Voter card settings • Ballot screen layout • Voting Rules • Report printer type • VVPAT option • Print of election information • QR codes • Electronic mobile ballot • AVS • Audible Tone • Timeouts • Battery • Write-in • Report • Report labels • Report header • Report body • Report footer • LED indicator light - configurable option • MCF version 6/18/2024 455 Version: 5.19::4 Appendix C - ImageCast® X Configuration Files Each category contains its own set of MCF options that can be configured to adhere to election requirements. C.1 Election Day ICX Configuration The default MCF file that is provided with the EMS release and imported into the project, is the file that should be used for the polling place (Election Day) ICX tabulators. C.2 Early Vote ICX Configuration The default MCF file that is provided with the EMS release and imported into the project, is the file that should be used for the early vote ICX tabulators. 6/18/2024 456 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions APPENDIX D: ELECTION EVENT DESIGNER SUPPLEMENTAL SETUP INSTRUCTIONS D.1 Jurisdictions Serviced by Dominion Voting For jurisdictions that will have their elections programmed by Dominion, the jurisdiction will receive the election database which they will then restore (refer to ® section 12.2.2“Restoring an Election Project”) on their Democracy Suite System. D.2 Jurisdictions Programming Their Own Elections Specific procedures on how to create their election project will be provided to each ® jurisdiction programming their own election via Democracy Suite System, after purchasing the system. Included in those specific procedures will be some specific steps that those jurisdictions will need to complete to ensure a successful programming of the election. Some of those specific procedures and tips are described in this chapter. D.2.1 Creating Election Project In the process of creating a new project in EED, the name of the project is defined. The name is not changeable after the project has been created, so the jurisdictions are advised to have the final name of the project defined in advance. D.2.1.1 Set Ballot Consolidation In an election project, ballots can be consolidated on different levels. Ballot Consolidation determines the method used for creating ballots in the project (e.g., by Precinct or by Ballot Type) and this will determine the number of unique ballots created in the project as well as whether ballots will need to be sorted prior to scanning. Consolidation is set for the lead card and for tail cards as desired. Ensure that you understand different types of consolidation and choose the most appropriate one for your jurisdiction’s needs. Ballot Consolidation is set in the ‘Project Parameters’ dialog window, and needs to be addressed during the Election Project Definition phase. For more information on consolidation types, ® and how to set it for your project, please refer to Democracy Suite EMS Election Event Designer User Guide, Section 3.7.3.1 “Ballot Generation Options”. NOTE: If you are unsure of which option to choose, please contact your Dominion Voting representative. 6/18/2024 457 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions D.2.1.2 Setting Header Watermark To set the watermark for header: • Open the template for the Ballot Content header. • Select File, and then select Page Setup. • From the Background Image section select the ‘...’ button and browse to the location of the saved image to be used. If the image is smaller than the document size, it will be repeated in the background so as to cover the width of the page. If you do not want the image to repeat, but to only display one image, you will need to adjust the image size to match the document’s size. Image width should be equal to the size of the text document multiplied by 72. TableD-1 lists available universal multi column ballot header widths: Grid Name Header Width (in) Picture Width (px) Right Side VB 10 ranks 7.25 522 (4 columns) Right Side VB 9 ranks (3 7.29 525 columns) Right Side VB 7 ranks (2 7.25 522 columns) Left Side VB Position (3 7.08 510 columns) Left Side VB Position (2 6.87 495 columns) Table D-1: Watermark Settings ® D.2.1.3 Maximum Number of Precincts to Associate to an ImageCast ® Evolution or ImageCast Precinct 2 Depending on the consolidation type selected in the election project, the number of ballots that is created for an election could be very large. This number will depend on a number of factors, including: number of precincts, number of languages and number of elector group combinations. For the Early Vote ICE and ICP2 tabulators, care needs to be taken with regards to how many precincts are assigned to each of those tabulators, in case when the number of ballots is very large. 6/18/2024 458 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions If the Early Vote ICE is configured to support accessible voting, ensure that ICE MBS is configured to Contest by Contest presentation of the ballot in the accessible voting session. For more information on the MBS and this option ® ® please refer to Chapter B“ImageCast Evolution and ImageCast Precinct 2 Machine Behavioral Settings”. D.2.1.4 Defining Counting Group Counting Groups are used to tabulate ballots from different groups of voters using separate groups. These may include Early Voting, Absentee/Mail (Vote By Mail) voters, and Election Day voters. Counting Groups are attached to tabulators and each tabulator can only be part of one Counting Group. The ‘Election Day’ Counting Group exists by default. For more information on Counting Groups and ® how to set them in your project, please refer to Democracy Suite EMS Election Event Designer User Guide, Section 6.4 Defining Counting Groups. D.2.1.5 Defining Tabulators For a typical election, a jurisdiction may need to create the following tabulators: • Election Day ICE - these tabulators will be used to process election day ballots at voting locations. Typically, you create one Election Day ICE per precinct, however, it is possible to connect more than one precinct to any ICE. • Election Day ICC - this tabulator will be used for processing Provisional Election Day ballots. Each ICC will typically handle all precincts and will be used for handling Provisional ballots. • Absentee\Mail ICC- this tabulator type will be used for processing Absentee and Mail ballots. These tabulators typically handle all precincts. • Early Vote ICE - this tabulator type will typically be used for processing early vote ballots before Election Day. • Election Day ICX BMD - these tabulators will be used to mark ballots at Election Day voting locations. Typically, you may create one or more Election Day ICX per precinct, however, it is possible to connect more than one precinct to any ICX. • Early Vote ICX BMD - these devices may be used for marking ballots at early voting locations before Election Day. • Duplication ICX BMD - these devices may be used for “duplication” of provisional ballots. ® For more details, please see Democracy Suite EMS Election Event Designer User Guide, Section 5.6 Defining Tabulators, and 5.5 Defining Tabulators in Batches. 6/18/2024 459 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions D.2.2 Creating Tabulators in the Ready for Elections Phase In certain situations, it may be necessary to create additional tabulators in the Ready for Elections phase, after election files have been already created. For example, if a tabulator was forgotten during the initial setup or an additional tabulator must be deployed at a polling place. 1. Any number of tabulators may be created in ‘Ready for Elections’. 2. After creating the tabulators, election files must be manually generated. Select the newly created tabulators, and then click the Generate Election Files button. D.2.3 Fonts, Languages and Ligatures Certain languages are scripted with ligatures put very simply, each character changes appearance depending on its position in the word, and the adjacent characters. Examples of such languages are Arabic, Bengali and Hindi, amongst others. To ensure such text is correctly displayed on the ballots, special steps must be performed in EED. In order to display language properly on the ballot headers and other templates in the project, an appropriate font must be selected for each of the languages. The following are examples of the most commonly used languages and their fonts: • English, Spanish, Tagalog: Arial Narrow • Chinese: MingLiu • Vietnamese: Arial • Khmer: Khmer • Punjabi: Raavi • Korean: Arial Unicode MS 6/18/2024 460 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions If you are unsure which font to use for a particular language, or have any other questions regarding language and related topics, please refer to Democracy ® Suite EMS Election Event Designer User Guide, Chapter 5 Styling an Election Project or contact your Dominion Voting representative. ® For more information see Democracy Suite EMS Election Event Designer User Guide, Appendix F - Rendering Text with Ligatures. D.2.4 Audio Studio Instructions If Audio Studio is used to produce an Audio Studio export file, import it into EED. ® Please refer to Democracy Suite Audio Studio User Guide, chapter 5 Defining an Audio Library. D.2.5 Creating Additional Audio Files for an Election Project At times it may become necessary to manually use the Cepstral audio synthesizer to create an audio file for an election project. Additional audio files can be created using the built-in front-end application (Swift Talker) that is packaged with Cepstral synthesizer used by EED. By selecting the same voices used for each language in the EED project being built, the additional audio material will be consistent with the audio that has already been created. Any missing audio content can be generated by copying & pasting the text for the missing audio string into the Swift Talker main screen, selecting the option to Export Audio file (File, Export Audio File) and saving the audio string as a WAV file(16 bit,11KHz,Mono option). The saved audio file can then be imported directly into the election project in EED or indirectly through an Audio Studio export package. CepstralSwifttalker will be installed on the EMS workstation and optionally on other trusted computers. D.2.6 Tabulator Threshold Settings It is advisable to check the scanner threshold settings are correct for each of the tabulators. To do this, the Technician needs to log into EED project and navigate to the Administrator menu item, System Settings, and then click Scanner Configuration.Default scanner settings might need to change depending on the ballot design or print method used to produce ballots. 6/18/2024 461 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions D.2.7 Programming of Election Files and Security Devices D.2.7.1 Programming of CF/SD Cards 1. Expand the ‘Tabulation’ Navigation menu and select the ‘Tabulators’ activity. Click Search on the Tabulation - Tabulators context sensitive screen to populate a list of all available tabulators. Note that each tabulator on this list will need to have memory cards programmed for it. 2. Double-click on a tabulator to open the Tabulator dialog window. 3. Click the Create Primary button. 4. Insert the CF/SD card into the card reader. If the CF/SD card is already inserted, remove the card and re-insert. 5. After initialization, the Election Event Designer will being copying the files to CF card. 6. Once the card is programmed, you will be notified with a dialog. Click OK to confirm and remove the card from the Compact Flash card reader. Be sure to label it. There is no need to remove it safely from the drive as you would a USB removable medium. 7. After creating the Primary memory card, you will create a blank backup memory card. 8. Click the Create Backup button and repeat steps 4 - 6. You will receive notification once the process is complete. 9. Repeat each step for every tabulator requiring memory cards. ® For more information, please refer to Democracy Suite Election Event Designer User Guide, Section 7.2.1 Programming Memory Cards. D.2.7.2 Programming of iButton Security Key 1. Expand the ‘Tabulation’ Navigation menu and select the ‘Tabulators’ activity. Click Search on the Tabulation - Tabulators context sensitive screen to populate a list of all available tabulators. 2. Double-click on a tabulator to open the Tabulator dialog. 3. Click on the ‘Users’ tab and select the ‘Admin’ user from the list of available users. Select the Program Security Key button. 4. A dialog will appear asking you to insert an iButton Security Key into the reader. Do so and then click OK. 5. You will receive confirmation that the iButton Security Key has been programmed successfully. Click OK. 6. Repeat these steps for each iButton Security Key you need to program. 6/18/2024 462 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions ® For more information, please refer to Democracy Suite EMS Election Event Designer User Guide, Section 7.2.2.1 Programming iButton Security keys. D.2.7.3 Programming Technician Smart Cards 1. Ensure you have opened your election project in EED as a user with an Administrator or Technician role. 2. Go to Settings > Project Parameters > Smart Card tab. See FigureD- 1. Figure D-1: Project Settings - Project Parameters window 3. Click View / Update for the Technician SC pin field. The Smart Card Pin dialog will appear. 4. In the User Password field, enter the password used for opening the election project, and then click Verify. 5. In the Pin field, enter the pin for the Technician Smart Card you wish to program, and then click Update Pin. See FigureD-2. NOTE: The Pin can only contain numerals, and must be at least 4 digits and at most 8 digits. 6/18/2024 463 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions 6. Click Close. Figure D-2: Smart Card Pin dialog 7. Back in the Smart Card tab of the Project Parameters dialog, click Program Smart Card, insert the card into the card reader, and then follow the prompts. D.2.7.4 Program USB flash drive for ImageCast X Devices Once election files have been created and the project is in ‘Ready for Election’, the EED user can program a USB flash drive containing the programming group election file by performing the following steps: 1. On the EMS Client Workstation, open the EED application. 2. In the left-hand pane, expand Tabulation and then click Programming Groups. 3. On the Programming Groups screen, click Search to populate programming groups. 4. In the Tabulator list, double-click ICX. 5. On the Programming Group dialog, leave all default settings and then click Program USB. The Waiting for USB to be inserted dialog opens, as shown in FigureD-3. Figure D-3: Waiting for USB to be inserted dialog 6/18/2024 464 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions 6. The system will present a dialog asking the user to insert a USB flash drive. Once inserted, EED will copy the data file to the USB removable medium and inform the user that the data is finished copying. 7. On the Information dialog, click OK. See FigureD-4. Figure D-4: Information dialog 8. The action can be repeated for any Election File programming groups. D.2.8 Programming of poll worker Smart Card You will need to use the EED application to program poll worker Smart Cards for the ImageCast X and for the ImageCast Voter Activation applications. Prior to programming your smart card, ensure that you have a Smart Card Reader connected to your EMS workstation and the required number of Smart Cards to be programmed. In addition, the appropriate Smart Card driver must be installed (this should come equipped as part of your qualified Smart Card Reader device), ® as must the Smart Card Helper Service as per the Democracy Suite EMS System Installation and Configuration Procedure document. Ensure you have opened your election project in EED as a user with an Administrator or Technician role. The following steps describe how to program Technician and poll worker Smart Cards: 1. On the EMS Client Workstation, open the EED application. 2. On the left-hand pane, expand Tabulation and select the Tabulators activity. Click Search on the Tabulation - Tabulators context sensitive screen to populate a list of all available tabulators. 3. Double-click on a tabulator to open the Tabulator screen. 4. Click on the Users tab, and then select the Admin user from the list of available users. See FigureD-5. NOTE: If you need to view the Admin PIN, double-click Admin. On the Tabulator User dialog, click Show PIN and then close the dialog. 5. Click Program Smart Card. 6. A screen appears asking you to insert a Smart Card into the reader. Insert the Smart Card, and then click OK. 7. You will receive confirmation that the Smart Card has been programmed successfully or error message if programming failed. Click OK. 6/18/2024 465 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions 8. Repeat these steps for each Smart Card you need to program. Figure D-5: Program Smart Card screen ® Programming of smart cards is explained in detail in the Democracy Suite EMS Election Event Designer User Guide, 7.2.2.2 Programming Smart Cards through 7.2.2.4 Programming poll worker Smart Cards. D.3 Exporting of Voter Activation Codes from EED ® Activation codes are used by the system when activating ImageCast Evolution voter sessions at a polling location. The EED application generates activation codes during the Ballot Content Generation process, which takes place during the transition from the Election Project Definition phase to the Election Project Styling phase. Codes are generated for any combination of Precinct Portion and Ballot Group in the election project. 6/18/2024 466 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions Activation Codes and relevant detail can be viewed and managed in the Activation Codes section, accessed from the Election Event menu in the left-hand navigation of the EED application. The screen displays the code, its description, as well as the associated Polling District, Ballot Type, Ballot Group and Cycle. Figure D-6: Activation Code screen 1. The user can edit the code and the description for each item in the list by either selecting it and clicking the Edit icon in the toolbar, or double-clicking the item. The Activation Code dialog will appear. 6/18/2024 467 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions 2. After ensuring that the new code is unique and the changes are made, click Save and Close to apply the changes. Figure D-7: Editing Activation Codes 3. If you have already created this file in EED and imported in ICVA, skip this step. Otherwise, open the election project in EED on your EMS workstation, and perform the next two steps: 4. In the Election Project menu, select the Export menu item and click the Activation Configuration item. Figure D-8: Exporting the Activation Code Configuration File 6/18/2024 468 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions 5. In the Save As dialog, navigate to the location where the file should be saved, and click Save. This file must be transported to the polling location computer where ICVA is running. Figure D-9: Saving the Activation Code Configuration File 6/18/2024 469 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions D.4 Importing Activation Codes to the ImageCast® Voter Activation Application When the ICVA application is successfully installed, the next step is to run the application and perform some basic configuration steps. Figure D-10: Insert poll worker Smart Card 1. To start the application, double-click the ICVA shortcut located on the desktop. 2. When the application starts, the user will be prompted to insert the poll worker smart card, in order to authenticate the user, see FigureD-10. Figure D-11: Enter Poll Worker Pin 6/18/2024 470 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions 3. When the card is inserted, the application will prompt the poll worker for the pin, in order to perform authentication, see FigureD-11. Figure D-12: Browse to Activation Code Configuration File 4. When the activation code configuration file has been imported, the ICVA application will display a configuration screen where the user can indicate: • Whether the polling application has facilities which provide for Accessible Voting Sessions. • Whether the polling location allows for provisional or challenge ballots to be cast. 5. The user must indicate the polling location they are at in the configuration screen. When all the settings have been applied, click Save. Now that the configuration steps have been completed, the application will be ready to accept voter smart cards for programming or reading. D.5 Programming of Voter Activation Smart Card In order to activate the voting session for a particular Ballot Type on the ® ImageCast Evolution, the Voter Activation Smart Card needs to be programmed ® from the ImageCast Voter Activation application. Programming of smart cards ® is explained in detail in the Democracy Suite EMS Election Event Designer User Guide, 7.2.2.2 Programming Smart Cards through 7.2.2.4 Programming poll worker Smart Cards. When the ICVA application has been started and configured properly, it will be waiting for the first Voter smart card to be inserted for programming. The following steps describe the typical card activation and reading cycle. 6/18/2024 471 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions • A prompt will be displayed to the poll worker, asking for a voter smart card to be inserted, see FigureD-13. Figure D-13: Insert Voter Smart Card 6/18/2024 472 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions • Select a Voter Session Activation Code. Otherwise, the poll worker can also click Exit if they wish not to proceed with activating the currently inserted card (next step). Figure D-14: Contents of the inserted Smart Card • On selecting Exit, the application will prompt the user to remove the smart card, see FigureD-15. Once it is removed, the poll worker will be presented with the situation in step 1 - the application will be waiting for a voter card to be inserted. The poll worker will be presented with a list of applicable activation codes and their descriptions for the polling location where ICVA is running. 6/18/2024 473 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions Figure D-15: Remove Ejected Card • Select the correct activation code for the voter, and click Activate Voter Card, see FigureD-16. Figure D-16: Selecting a Voter Session Activation Code 6/18/2024 474 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions • If ICVA has been configured to support activation of Accessible Voting Sessions (AVS) at the polling location where it is running, the poll worker will be prompted for the type of session to activate: Standard or Accessible. Click the button representing the correct session type for the voter to move to the next step, see FigureD-17. Figure D-17: Indicating if Voter Session is Accessible 6/18/2024 475 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions • If ICVA has been configured to support challenged voting at the polling location where it is running the poll worker will be prompted for the type of session to activate: Regular or Challenged. Click the button representing the correct session type for the voter to move to the next step, see FigureD-18. Figure D-18: Indicating if Voter Session is Challenged • The application will indicate that the selections are currently being written to the voter card, and the user will be instructed not to remove the smart card 6/18/2024 476 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions Figure D-19: Programming Voter Card • The application will inform the user that the card has been successfully programmed. Figure D-20: Card Successfully Written 6/18/2024 477 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions • The application will prompt the user to remove the smart card. Once it is removed, the poll worker will be presented with the situation in step 1 - the application will be waiting for a voter card to be inserted. Figure D-21: Remove Written Card D.6 Smart Card Security Recommendations ® The ImageCast X systems utilize smart cards for voter activation with the ® ImageCast X system additionally using specific smart cards to enable poll worker and technician functionality. The contents of these cards are encrypted and are usable only for the election for which they were programmed. Accessing ® poll worker or technician functionality on the ImageCast X system requires the physical smart card programmed for the election be loaded on the machine, as well as an election-specific password. Overall system security can be enhanced by creating procedures that implement the following security recommendations: • Label all smart cards with a unique serial number • When not in use, secure all smart cards from unauthorized access. • Consider attaching poll worker and technician cards to retractable lanyards that can be worn by authorized personnel while at the polling location. This help maintain positive control of the cards and guard against unauthorized access. • Regularly inventory poll worker and technician cards throughout the day during their use in the polling location. If a card is not accounted for during inventory, immediately notify election officials. 6/18/2024 478 Version: 5.19::4 Appendix D - Election Event Designer Supplemental Setup Instructions • Check in and out voter activation cards before and after use by a voter. What to do with a card that was not accounted for during a regular inventory but is later located: • Voter activation cards may be reused after they are inserted into the ® ImageCast Voter Activation station and activated for a new voter. The ® ImageCast Voter Activation station deletes the smart card's contents as part of its activation procedure. • Poll worker or technician cards should be taken out of use, if practical, until they can be reprogrammed using EMS Election Event Designer. Reprogramming a poll worker or technician card erases the card's contents before writing the necessary information back to the card. 6/18/2024 479 Version: 5.19::4 Appendix E - InterScan HiPro Scanner Handling Checklist APPENDIX E: INTERSCAN HIPRO SCANNER HANDLING CHECKLIST The following table provides a checklist for scanner handling guidelines. Scanner Handling Preparation Folded Ballots are to be flattened as much as possible to improve feeding speed and reduce potential issues. Input Tray Ballots stacks should not be higher than the paper guides in the input trays. The Paper Guide Extensions, for higher stacks, should not be used Folded ballots have to be placed to the input tray with the front edge upwards (first fold downwards). This improves feeding and output stacking If the number of double feeds or feed-in issues increases, the set of input/separation rollers should be changed and cleaned Double Feed See “InterScan HiPro Scanning Errors” on page485. Paper Jam Use of error handling on scanner. (See Troubleshooting section) Table E-1: Scanner Handling 6/18/2024 480 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution APPENDIX F: TROUBLESHOOTING AND PROBLEM RESOLUTION F.1 ImageCast® Evolution Troubleshooting NOTE: Any troubleshooting procedures required to be performed on Election Day MUST be performed in the presence and with permission of the Election Staff on duty. F.1.1 Replacing a Machine To replace a machine during an active election, follow the steps described below in presence of an authorized poll official: 1. Record the number of ballots displayed in the Ballot Counter. 2. Navigate to the Poll Worker menu. 3. Turn off the machine by pressing the Power Down icon on the top right corner of the Touchscreen LCD followed by the Shut Down tab. Otherwise, this step can be disregarded. 4. Lay down the Touchscreen LCD into its storage position then press the Service ON/OFF switch into the OFF position in order to completely shut down the unit. 5. Ask the voting official to remove the two (2) Election memory cards from the poll worker port and the administrative port. 6. Lift the machine off from the ballot box and record it for diagnosis. 7. Place the two (2) memory cards into their respective ports of the replacement unit. 8. Place the replacement unit on the Ballot Box. 9. Lock the tabulator in place. 10. Lift the Touchscreen LCD of the replacement unit into its operating position then press the Service ON/OFF switch onto the ON position to power it up. 11. On the Insert Security Token Screen prompt, place a valid administrative key on the Security Keypad. 12. Type in the correct credentials to access the Election Application Main Menu. 13. Select the Open Poll tab (in the Main Menu), followed by selecting Open under Poll Status (in the ICE Poll-Worker menu). 6/18/2024 481 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution 14. Enter the correct credentials to Open the Polls in the new machine. The system will display a Warning message indicating that the ballot results already exist. Press the OK button to proceed to the ICE Poll- Worker Menu. 15. In the Main Menu, select the Utilities button followed by Report in order to print an Interrupt Report. Verify that the Total Voters Count on the Interrupt Report matches the “Ballot Counter” number you recorded in Step 1. 16. Remove the paper printout from the original machine and hand it to the Poll Official for the permanent record. 17. Ensure that the Poll Official places security seals on the CF1 Door and CF2 Door as required by their jurisdiction. 18. The replacement unit is ready for operation. To proceed, select the desired option on the main menu. Follow standard close poll procedures at the end of voting. F.1.2 Paper Jams In the event of a paper jam, the system runs a self un-jam routine to eject the paper and return it to the user for re- feed. An error message is displayed if the un- jam routine fails to clear the paper jam. The paper jam can occur either in the Scanner path or the Printer path. Visually, identify the location of the Paper Jam then refer to the appropriate section below to resolve the issue. F.1.2.1 Paper Jam in Scanner Path • If the ballot is visible from either the front ballot entry slot, or any of the two diverter slots on the bottom of the unit: • Gently pull the ballot out. Ensure that the ballot does rip or tear in the process. • If you removed the unit from the ballot box to access the jammed ballot, place the unit back onto the ballot box. • Be sure to properly account for the jammed ballot, placing it in the ballot box if it has already been cast (this is unlikely) or placing in the ballot entry slot so that it can be tabulated. • Replace the unit if the jam reoccurs. • If the ballot is stuck within the machine and is not visible from any of the accessible slots: • Place the iButton Security Key on the Security Keypad and insert the appropriate credentials. • The machine will automatically run the unjam procedure to clear the ballot jam. 6/18/2024 482 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution • If this fails to resolve the issue, replace the unit. Figure F-1: The Ballot Path (Scanning) F.1.3 Power Failures In the event of a power failure, the unit automatically switches to its internal battery. If the machine fails to turn on, or if the battery drains, check the connectivity and/or charge capacity of the battery. If this fails to resolve the issue, perform any of the procedures outlined below. F.1.3.1 Faulty Main's Power Source To identify whether the wall outlet is functional: • Plug in any other electrical product into the outlet and check if it powers up. • If the other electrical product fails to power up, plug the ICE unit to another wall outlet and confirm power up. • If the other electrical product powers up, refer to section F.1.3.2“Faulty or Disconnected Power Adapter”. F.1.3.2 Faulty or Disconnected Power Adapter Obtain permission from an authorized Election Official to gain access to the Ballot Box in order to inspect the power adapter. • Check cable connectivity • If cables are connected, measure the voltage (at the 2.5mm power pin), which should read 20V DC. If this is not the case, replace the power adapter. • If this fails to resolve the issue, replace the unit. F.1.4 Thermal Printer Issues related to this printer are very minimal. The primary causes of concern are discussed below. 6/18/2024 483 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution F.1.4.1 No Print on Thermal Paper or Printer Fails to Print In order to resolve this issue, follow the check sequence below: • Verify that the thermal paper is seated in the correct orientation in the Printer compartment. Because thermal paper can only be printed on one side, it is important that the paper roll sits such that it rolls along the Printer Compartment base surface and protrudes upwards and through the slot on the compartment door as indicated by the arrow in the figure below. • Verify that the Thermal Printer is receiving power by checking for a green LED on the Printer mechanism. If the green LED is off, ensure that the cables are properly plugged into the printer mechanism. • If this fails to resolve the issue, replace the unit. Figure F-2: Thermal Printer X-section View F.1.4.2 Thermal Printer Prints Invalid Characters To resolve this issue, check to ensure that the cables are plugged in properly into the printer mechanism. If this fails to resolve the issue, replace the ICE unit. F.1.5 Touchscreen Failures Touchscreen failures are associated with loss of calibration on the touchscreen. Common symptoms include: • Wrong button selected when attempting to press a particular button. • No response at screen touch. 6/18/2024 484 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution F.2 ImageCast® Central Troubleshooting F.2.1 Ballot Scanning Errors F.2.1.1 Ambiguous Errors NOTE: All ballots that cause any of the ballot scanning errors listed below are saved in C:\Projects\Project_Name\NotCastImages as images for further examination. The information message indicating that 'Ambiguous' may display during scanning. It informs the user that an ambiguous mark has been detected and the number of ballots that have not been counted as a result of the ambiguous mark. If this occurs do the following steps: ® 1. Close the ImageCast Central application. 2. Turn off the scanner. 3. Wait 1 minute. 4. Turn the scanner back on. ® 5. Open the ImageCast Central application again and resume scanning. 6. If the problem persists, please contact your Dominion Voting Representative. F.2.1.2 InterScan HiPro Scanning Errors If the InterScan HiPro scanner encounters an error while scanning the ballots, an error message stating “Sheets inside” appears on the scanner's LCD screen. Next to the “Sheets inside” statement are a green number and a red number: • Green number: Indicates the number of ballots successfully scanned and sent to the ICC application. These ballots do not need to be rescanned. • Red number: Indicates the number of ballots inside the scanner (scanned or not scanned) but not sent to the ICC application. These ballots need to be rescanned. An example of a scanning error message appears below. 6/18/2024 485 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution NOTE: Please note, the error description will vary depending on the nature of the scanning error but will always contain the statement “Sheets inside” along with the two numbers. Figure F-3: Example Error Use the following applicable procedures to resolve the issue. Scanner Error Handling by Error Sheet Count Use this procedure if you are not using the scanner's Post-Imprinter. 1. Make note of the green and red numbers on the error message screen. 2. From the scanner's error message screen, tap Transport. The problem ballots are automatically moved from inside the scanner into the output tray. 3. Count the ballots as they are moved into the output tray until the number equals the green number stated on the error message screen. These ballots remain in the output tray. 4. Remove from the output tray all proceeding ballots. The total count of these ballots equals the red number on the error message screen. 5. Return these ballots to the input tray. 6. Rescan the ballots. F.3 EMS Troubleshooting If any issues are encountered while configuring the EMS Application Server (EMS APPS) using DCM, please try the following troubleshooting procedure: 1. Start SQL Server Configuration Manager console. 6/18/2024 486 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution 2. Change 'log on as user' to Local System and click Apply. 3. Restart SQL Server Service. 4. Start SQL Server Agent service if it is available. 5. Start Computer Management console and navigate to 'Local Users and Groups'. 6. Delete the following user accounts: • emssqluser • emsdbusers group 7. Reboot the computer. 8. Run DCM again. 9. If the problem persists, please contact Dominion Technical Support. If the EMS system becomes unresponsive during any interaction with the operator, please follow the steps below to recover from that state: • Make sure that all servers you are using are switched on and working, and that all network equipment (if any) is switched on and working. • Make sure that all client computers you are using are switched on and working. • For any problems encountered during installation, make sure you followed the installation and configuration manual for both the server and the client computers. • Try to log in to the server you are using with the default administrator account. Open Task Manager (press Ctrl+Alt+Delete and click on the Start Task Manager button). Under the Process tab, make sure that no process that begins with the name "DVS" occupies 0% of CPU usage. If so, select that process and click on the End Process button at the bottom. Repeat the process, if necessary. • Try to log in to each client computer you are using with the default administrator account. • Open EED client application. Ensure that the entered EMS database and network settings, as well as the application user accounts, are correct. Check to see if the election event properties have been entered correctly. Create and then ensure the System and Audio Log reports are correct. • Open RTR client application. Ensure that the entered EMS database and network settings are correct. Ensure the transfer point parameters are correct. Reboot the server and try again. • Reboot the defective client computer(s) and try again. • If the problem persists, please contact Dominion Technical Support. 6/18/2024 487 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution F.3.1 Submission and Publishing of Batches This workaround explains how to recover from an instance where the submitted batches in Adjudication show “Submission Error”. When this happens, the batches will remain in the “Review” pane of the Adjudication application, with a “Submission Error” note next to the name of the batch. The submission error problem will usually affect multiple batches of consecutive batch numbers. Note the starting and the last affected batch number. Open the project in the RTR application and list all batches for the affected tabulator (you can find the tabulator name in the batch name in the Adjudication application). Highlight all the affected batches using the batch numbers noted in the previous step. Once the affected batches are highlighted, click on the Reject button. Go back to the Adjudication application and re-submit those same batches by dragging and dropping them into the Submitted pane of the Adjudication application. Go back to the RTR application and verify that the newly submitted batches are in Published/Adjudicated state. F.4 ImageCast® X Troubleshooting NOTE: Any troubleshooting procedures required to be performed on Election Day MUST be performed in the presence and with permission of the Election Staff on duty. F.4.1 Power failure In the event of a power failure, the unit automatically switches to its internal battery. Additionally, the device is equipped with a UPS that can power the unit and the BMD printer. F.4.2 Printer paper jam In the case of printer paper jam, consult the printer user guide. • HP LaserJet Pro M402dne - http://h10032.www1.hp.com/ctg/Manual/ c04639074 F.4.2.1 Low Toner If the printer is low on toner, printing functionality is suspended and an error message is displayed to the voter. The voter is prompted to contact the poll worker to resolve the issue and resume printing. To Replace the Toner Cartridge: • Insert the poll worker card and enter the access code. 6/18/2024 488 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution • The ICX Warning dialog displays the Print Status error "Cartridge toner is low". • Replace the toner cartridge. For detailed instructions, please the Remove and replace the toner cartridge section, on page 29, of the HP "LaserJet Pro M402, M403" user guide. • Printing can resume when the control panel's Ready light is green. "Ready" will also be visible in the control panel display. • On the ICX screen, press Reprint. • Remove the poll worker smart card. F.4.3 Replacing BMD printer To replace a BMD printer on Election Day, follow the steps described below in presence of an authorized Poll Official: 1. Power off the printer. 2. Disconnect the USB and power cable from the printer. 3. Remove the printer. 4. Place the replacement printer into the same location. 5. Reconnect the USB and power cable to the replacement printer. 6. Log in using a Technician Smart Card. 7. Select Hardware Information to verify the printer is present. If an error occurs, start the procedure from the beginning. 8. Select Hardware Test and then Printer test. 9. Print a test page to confirm the printer is working. If an error occurs, start the procedure from the beginning. 10. Remove the Technician Smart Card. 11. The device is ready to receive Voter Smart Cards. F.4.4 Replacing ICX device To replace ICX device on Election Day, follow the steps described below in presence of an authorized Poll Official: 1. Record the number of ballots displayed in the Ballot Counter. 2. If you are in the “Poll-Worker Menu” or “Tech Menu”, turn off the machine by pressing the Power Down icon on the bottom right corner of the menu and then selecting option Yes. Otherwise, this step can be disregarded. 3. Disconnect the power cable, printer cable, and ATI device, if it's connected. 6/18/2024 489 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution 4. Once you have checked there are no more obstacles, remove the device from the table. 5. Place the replacement unit on the table. 6. Attach the printer cable and the ATI cable, if ATI was connected previously. 7. Plug the power cable into the device. 8. Wait for the device to power up. 9. Insert the Technician Smart Card and log in. 10. Confirm or modify the date and time. 11. Make sure the device has valid election files loaded, if not, load valid election files from a USB removable medium. 12. Remove the Technician Smart Card. 13. Make sure no USB removable mediums are in the device. 14. Close the trap doors and place the seals at the security latches. 15. Insert the poll worker Smart Card and Select the desired tabulator from drop down list. 16. Select the Open Poll option (in the Main Menu), and confirm the poll opening. 17. Remove the poll worker Smart Card. The replacement unit is ready for operation. To proceed, insert a valid Voter Smart Card. Follow standard close poll procedures at the end of voting. 6/18/2024 490 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution F.4.5 Errors During Printing If the ICX encounters an error during printing and prints an incomplete ballot (i.e. missing the QR code or list of human-readable selections), the pollworker can To resolve: 1. The poll worker must spoil any incomplete ballots. 2. To power cycle the ICX: a. Insert your poll worker smart card and log in to the ICX. b. From the bottom-right, click Power off. c. From the Power off window, tap Power off. d. On the confirmation message, tap Yes. e. After the ICX has been powered down for 10 seconds, to turn it on, press the power button located behind the accessories door. Accessing the power button will require breaking the security seal on the accessories door, follow your jurisdiction’s procedure for replacing security seals. 3. Reissue a new activation card to the voter and ask the voter to begin a new voting session. F.5 ImageCast® Precinct 2 Troubleshooting The following sections discuss handling common tabulator hardware issues. F.5.1 Power-up/Set-up Issues F.5.1.1 Tabulator Does not Power-up 1. If the ICP2 tabulator does not power-up upon pushing and holding the reset button, perform the following: 2. Check the back of the tabulator to ensure that the DC power adaptor is plugged into the tabulator's power port. 3. Confirm the power socket is functional. 4. Confirm the ICP2 service switch, behind the Administrator SD door is switched to the on (down_ position). 5. If the ICP2 still does not power-up when the reset button is pressed and held, contact election technical support for assistance. 6/18/2024 491 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution F.5.1.2 Security Key (iButton) Error If you receive the message "Error Reading Admin Key": 1. Firmly press the security key to the receptacle again, ensuring complete contact. 2. If the error message continues, contact election technical support for assistance. F.5.2 Report Printer (Thermal Printer) Issues F.5.2.1 Thermal Tape Printer Error - Loose Pressure Roller 1. When the pressure roller is loose or installed incorrectly, the message "Make sure paper is loaded and everything is OK" appears. 2. If necessary, remove the thermal report printer door security seal. 3. Open the thermal report printer door. 4. Remove and reinstall the platen pressure roller over the paper tape. 5. Ensure you hear the pressure roller click into place. 6. Close the printer door. 7. Attempt to reprint the report. 8. Reseal the door. F.5.2.2 Thermal Tape Printer Error - No Paper Loaded When the printer runs out of paper, the message "Make sure paper is loaded and everything is OK" appears. 1. If necessary, remove the thermal report printer door security seal. 2. Open the report paper access door on the tabulator. 3. Pull up on the platen pressure roller to remove it. 4. Replace the paper and then re-insert the platen pressure roller on top of the paper. 5. At the LCD screen, press OK. The message "Printer is recovering! Please Wait" appears. 6. Wait long enough to let the printer recover and press OK. 7. Replace the security seal. 8. If the problem still exists, contact election technical support. 6/18/2024 492 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution F.5.2.3 Report Tape not Printing on Thermal Paper Confirm the paper is installed correctly. Follow the instructions in Replacing the Thermal Printer Paper Roll to correctly install the printer paper. Check to ensure that there is paper loaded into the thermal printer. Refer to Replacing the Thermal Printer Paper Roll for instructions detailing how to install printer paper. F.5.3 Scanner (Tabulator) Issues F.5.3.1 Scanner (Tabulator) Does not Accept Ballots If the scanner (tabulator) is not operating: 1. Open the auxiliary ballot compartment slot and have voters manually insert their ballots into the slot. 2. Call Election technical support. 3. When the scanner (tabulator) is operational again, or is replaced: 4. Close and seal the auxiliary compartment slot. 5. Remove these ballots from the Auxiliary compartment before closing of polls, and handle them as per jurisdictional procedures. F.5.4 Tabulator Paper Jam When scanning the voters ballot, paper jams are rare events but can occur. If a paper jam occurs on Election Day, the tabulator reports it on the tabulator screen. Three different paper jam conditions can occur: • Input slot • Exit slot • On startup In the event of a paper jam, you must carefully read the tabulator screen to know whether or not the ballot scan results have been registered and saved. F.5.4.1 Input Slot Paper Jam An input slot paper jam occurs when a ballot is inserted into the tabulator before the previous ballot has registered its result. 6/18/2024 493 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution To resolve an input slot paper jam: 1. Read the error message. 2. If the ballot is accessible from the front, gently pull it out. NOTE: Voter privacy is maintained when pulling the ballot out manually. 3. If the ballot is not accessible from the front of the tabulator, lift the tabulator and pull the ballot out from the front or wherever easily accessible. NOTE: Exercise care when manually pulling the ballot to avoid tear. If any resistance is felt while pulling the ballot, stop and contact Election Technical Support. 4. Press CLEARED on the tabulator screen. The Main Menu screen displays. 5. Re-insert ballots that were not tabulated. NOTE: Ballots can be re-inserted only if the ballot edges are not visibly damaged. Otherwise, a new ballot must be issued. 6. If the ballot is not accessible from either slot, contact Election Technical Support. NOTE: If the Main Menu screen does not display when cleared, contact Election Technical Support. Once the paper jam is cleared, the tabulator automatically attempts to finish processing the initial ballot. When successfully completed, the second ballot is ejected from the input slot. F.5.4.2 Exit Slot Paper Jam An exit slot paper jam occurs when a ballot has been registered but becomes stuck in the exit slot. The results could either be saved or not saved. 6/18/2024 494 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution To resolve an exit slot paper jam: 1. Read the error message. 2. If the ballot is accessible from the rear, gently pull it out. NOTE: Voter privacy is maintained when pulling the ballot out manually. 3. If the ballot is not accessible from the rear of the tabulator, lift the tabulator and pull the ballot out from the rear or wherever easily accessible. NOTE: Exercise care when manually pulling the ballot to avoid tear. If any resistance is felt while pulling the ballot, stop and contact Election Technical Support. 4. A Clearing Jam... message displays on the screen. Wait until the tabulator processes your actions. 5. If the paper jam has not been cleared, an Assistance Required message displays. Seek assistance to resolve the paper jam. 6. If the paper jam persists, a Paper Jam Unresolved message displays. Your results could either be saved or not saved. 7. A Checking Paper Jam... message displays. When cleared, press CLEARED on the tabulator screen. The Main Menu screen displays. 8. If the ballot is not accessible from either slot, contact Election Technical Support. NOTE: If the Main Menu screen does not display when cleared, contact Election Technical Support. Ensure the following: • If the ballot scan results were saved, drop the ballot into the appropriate compartment of the ballot box. If the ballot scan results have not been saved, pull the ballot from the rear slot and rescan the ballot. • If the results were saved and the ballot was pulled out from the rear slot, drop it into the main compartment of the ballot box. • If the results were saved and the ballot was pulled out from the bottom slot, drop it into the secondary compartment (write-in compartment). • If the issue is resolved, wait for the next voter to insert their ballot. If the issue repeats, contact Election Technical Support. 6/18/2024 495 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution F.5.4.3 On Startup Paper Jam An on startup paper jam occurs when you shut down a tabulator in the middle of a paper jam without resolving the issue and restart the tabulator at a later time. The results could either be saved or not saved. To resolve an on startup paper jam: 1. A Paper Jam Detected message displays. When cleared, click Clear Jam. NOTE: Voter privacy is maintained when pulling the ballot out manually. 2. If the paper jam is not cleared, a Paper Jam Still Exists message displays. If the ballot is accessible from the front or rear, gently pull it out. When cleared, click the Cleared button. 3. If the ballot is not accessible from the front or rear of the tabulator, lift the tabulator from the ballot box and pull the ballot out from the front or rear or wherever easily accessible. NOTE: Exercise care when manually pulling the ballot to avoid tear. If any resistance is felt while pulling the ballot, stop and contact Election Technical Support. 4. Press CLEARED on the tabulator screen. The Main Menu screen displays. NOTE: If the Main Menu screen does not display when cleared, contact Election Technical Support. 5. If the ballot is not accessible from either slot, contact Election Technical Support. Ensure the following: • If the ballot scan results were saved, drop the ballot into the appropriate compartment of the ballot box. If the ballot scan results have not been saved, pull the ballot from the rear slot and rescan the ballot. • If the results were saved and the ballot was pulled out from the rear slot, drop it into the main compartment of the ballot box. • If the results were saved and the ballot was pulled out from the bottom slot, drop it into the secondary compartment (write-in compartment). • If the issue is resolved, wait for the next voter to insert their ballot. If the issue repeats, contact Election Technical Support 6/18/2024 496 Version: 5.19::4 Appendix F - Troubleshooting and Problem Resolution F.6 Reporting Troubleshooting This section describes how to resolve reporting issues. F.6.1 Batch Selection List Does Not Refresh Immediately During the results reporting period, the desired batch does not appear in the list. When in the Results Reporting section, the batch selection listing of individual batches loaded to the system (see FigureF-4) may not refresh immediately. To resolve this, follow the steps below. Figure F-4: Batch selection list When generating a report for a specific, selected batch, perform the following steps to refresh the list of batches: 1. Run any other report. The list of batches is refeshed. 2. Close and relaunch the RTR application. 6/18/2024 497 Version: 5.19::4 Appendix G - Threat Register APPENDIX G: THREAT REGISTER The following list outlines potential threats and vulnerabilities that relate to critical information assets (i.e. digital records). Only information assets that have their communication vulnerability attribute set to ‘Yes’ are considered for possible vulnerability exploitation. Tampering with Election Definition • Description: In addition to the EMS Database which stores election project definition in the form of a relational database, election definition is contained within the election definition files. These files are generated by the EMS platform and communicated with the target PCOS/ICC devices using memory cards. Each memory card is unique to the target PCOS/ICC instance. • Threat: A malicious user decrypts, discovers, and modifies election definition files/database between file creation and ballot counting. • Impact: By changing the election definition files or database, the malicious user (technician, poll worker) can make the voting system inaccurate or inoperable. Confidentiality of election data is of less concern in this case, considering that election definition data is usually publicly available information. • Impacted Security Pillars: Integrity and availability. • Risk Rating: High. • Mitigation: Implement proper process (access control) for memory card handling and unit storage. Cryptographic and digital signing controls mitigate data tampering. This tampering would be evident to operators and voters. Tampering with Device Configuration • Description: In addition to election definition files, the EMS platform provides PCOS/ICC devices with DCFs (Device Configuration Files) in case of ICC, and MBS (Machine Behavioral Settings) files in case of ICE and ICP2. These files do not carry any election project related logic, however, they are important for proper functioning of the devices. • Threat: A malicious user decrypts, discovers, and modifies DCF or MBS files. • Impact: By changing DCF/MBS files, a malicious user (technician, poll worker) can make a PCOS/ICC device inoperable. • Impacted Security Pillars: Integrity and availability. • Risk Rating: High. 6/18/2024 498 Version: 5.19::4 Appendix G - Threat Register • Mitigation: Implement proper process (access control) for memory card handling and unit storage. Cryptographic and digital signing controls mitigate data tampering. The DCF and MBS files are paired with corresponding .SHA files that are created at the time the DCF/MBS files are created.The .SHA file includes a SHA-256 value that is seeded with a Dominion private input vector.When Election Event Designer imports the DCF/MBS files into an election project, it verifies the integrity of the DCF or MBS file against its .SHA file. EED generates a SHA-256 value with the Dominion private input vector and compares that against the .SHA file. If the verification fails, Election Event Designer will refuse to import the DCF/ MBS file and will display an appropriate error message indicating that the verification was not successful.As such, this tampering would be evident to operators and voters. Tampering with Ballot Representation • Description: In addition to election definition, election database, device configuration files and machine/ device behavioral settings, the EMS platform provides PCOS devices (except ICC) with ballot representation files. These files represent electronic versions of paper ballots and include PNG (electronic image of the paper ballot for display presentation) and XML (coordinates of the ballot elements) files. Ballots in PDF format are not used by devices, but represent ballot format data for the mass printing of ballots.Finally, there is an audio representation of the ballot content, which is provided to the ballot counting or marking device. It is important to note that these ballot presentations are used only when PCOS devices provide AVS capabilities. • Threat: A malicious user decrypts, discovers, and modifies ballot representation files. • Impact: By changing ballot representation files, a malicious user (technician, poll worker) can make a PCOS/ ICC device inaccurate. Confidentiality of election data is of less concern since election definition data is usually publicly available information. • Impacted Security Pillars: Integrity. • Risk Rating: Medium. • Mitigation: Implement proper access control measures for memory card handling and unit storage. Cryptographic and digital signing controls mitigate data tampering. This tampering would be evident to voters 6/18/2024 499 Version: 5.19::4 Appendix G - Threat Register Tampering with iButton Security Keys • Description: iButton Security Keys represent secure electronic tokens used to activate administrative functions of the voting device (open poll, close poll, diagnostics, start accessible vote session, etc.). The iButton Security Keys carry electronic representation of the administrative poll worker password. • Threat: A malicious user decrypts, discovers, and uses iButton Security Key content. • Impact: By discovering the content of the iButton Security Key, a malicious user (technician, poll worker) can activate administrative operations on the device. The likelihood of this action is low because the malicious user would also have to know the password to access the iButton Security Key content. • Impacted Security Pillars: Integrity, Availability. • Risk Rating: High. • Mitigation: Implement proper process (access control) for iButton Security Key handling and storage. Cryptographic and digital signing controls mitigate data tampering. This tampering would be evident to operators and voters. Tampering with Device Audit and Log Reports • Description: During the voting session, PCOS/ICC devices constantly keep and update audit and log reports. These reports are important for the analysis of the system functions and also for the audit process. • Threat: A malicious user decrypts, discovers, and modifies the content of the audit and log reports. • Impact: This threat is more likely to occur in combination with some other threats (like voting results tampering) with the main goal to cover up any malicious actions. • Impacted Security Pillars: Confidentiality and integrity. • Risk Rating: Medium. • Mitigation: Implement proper process (access control) for memory card handling and unit storage. Cryptographic and digital signing controls mitigate data tampering. This tampering would be revealed during auditing. Tampering with Scanned Ballot Images • Description: During the voting session, PCOS/ICC devices constantly record images of the scanned paper ballots. It is important to state that in paper based voting systems, such as PCOS/ICC platforms, a paper trail of the ballots always exists in the form of the original paper ballots. 6/18/2024 500 Version: 5.19::4 Appendix G - Threat Register • Threat: A malicious user decrypts, discovers, and modifies scanned ballot images. • Impact: This threat is more likely to occur in combination with some other threats (like vote results tampering) with the main goal to cover up any malicious actions. • Impacted Security Pillars: Confidentiality and integrity. • Risk Rating: Medium. • Mitigation: Implement proper process (access control) for memory card handling and unit storage. Cryptographic and digital signing controls mitigate data tampering. This tampering would be evident to operators. Tampering with Election Result Files • Description: Election result files hold the up-to-date raw and tabulated (per voting device) voting results and it is imperative to protect their content. • Threat: A malicious user decrypts, discovers, and modifies election result files, and, within the proper chain of custody, replaces the valid memory card with a tampered card produced by the ballot counting device. • Impact: By changing these files, a malicious user would jeopardize the whole election event. • Impacted Security Pillars: Confidentiality and integrity. • Risk Rating: High. • Mitigation: Implement proper process (access control) for memory card handling and unit storage. Chain of custody for memory cards with results as well as cryptographic and digital signing controls mitigate data tampering. This form of tampering is immediately evident when the voting machine paper record (printout) is compared to the memory card results. Tampering with Transmitted Election Result Files • Description: Election result files hold the up-to-date raw and tabulated (per voting device) voting results and it is imperative to protect their content. • Threat: A malicious user decrypts, discovers, and modifies election result files, before, during, or after transmission, and, within the proper chain of custody, replaces the valid results with those that have been tampered with. • Impact: By changing these files, a malicious user would jeopardize the whole election event. • Impacted Security Pillars: Confidentiality and integrity. • Risk Rating: High. 6/18/2024 501 Version: 5.19::4 Appendix G - Threat Register • Mitigation: Implement proper cryptographic signing controls to detect tampering. This form of tampering is immediately evident when the voting machine paper record (printout) is compared to the tampered results. Tampering with EMS Data Center Environment • Description: Physical or logical destruction of the EMS Data Center equipment. • Threat: Due to unexpected or intentional activities, prior or after the election night (i.e. during election preparation or during the results tally), EMS Data Center equipment could become inoperable. • Impact: Postponing the election event preparation and/or result processing and reporting. • Impacted Security Pillars: System availability. • Risk Rating: Medium. • Mitigation: Proper redundancy and backup procedures for hardware, software and data should be in place to mitigate the risk from intentional or unexpected destruction of the EMS Data Center equipment. Tampering with Election Database • Description: Logical destruction and/or alteration of EMS Database content or structure. • Threat: A malicious attacker can try to infiltrate the EMS Database system to perform the destruction or alteration of the election data prior, during or after voting. This can be done remotely or internally if attacker has help from an insider.In this case, the validity of the election event becomes questionable. • Impact: Invalidation of the election event. • Impacted Security Pillars: Data integrity, data confidentiality, access control. • Risk Rating: Medium. • Mitigation: Proper design of the underlying election software and hardware shall prevent or detect this type of attack. In case of Democracy Suite, all in- transit data is encrypted and signed, while the database platform implements per-record signing of data using atomic triggers with every transaction. Coupled with auditing mechanisms, this approach prevents and detects any attempt to break into the database. Producing Incorrect Vote Counts • Description: Attacker gains access to the results acquisition and tally computing platform, and changes the voting results. 6/18/2024 502 Version: 5.19::4 Appendix G - Threat Register • Threat: Depending on the skill set and level, the attacker can try to break into the result acquisition and tally system directly or remotely and change the votes. This can happen after the results have been imported into the system but before persisting the results into the election results database. • Impact: A successful attack of this type would produce erroneous and invalid election results and invalidate the whole election event.An attack of this type would require a high level of computing skills and usually involves internal jurisdiction personnel or a vendor technical team. • Impacted Security Pillars: Access Control, Data Integrity and Data Confidentiality. • Risk Rating: High. • Mitigation: As stated earlier, this type of attack would require that the attacker has significant level of technical skills and knowledge of the system. In addition, if all the access control and data security measures were followed together with the system hardening procedures, this type of attack would require that attacker has helpers either within the jurisdiction or from vendor technical team.Therefore, to mitigate this type of attack it is important to follow the best security practices including access security, physical security, IT system security and auditing (including monitoring), data integrity and confidentiality. Tampering with EMS System Availability • Description: Make EMS Data Center and its computing components unusable for either pre-voting or post-voting activities. • Threat: In this case the attacker performs a destructive action either by direct manipulation of the EMS Data Center system components or by installing malicious software components that will make EMS Data Center components inoperable. • Impact: If the EMS Data Center components are not operational or not capable of performing their set of predefined activities, the jurisdiction either will not be able to organize the election event or to tally and report election results. • Impacted Security Pillars: System availability. • Risk Rating: Medium. • Mitigation: Proper access control and physical security shall prevent physical and logical destruction of the EMS Data Center system.Proper availability and disaster mitigation and operation continuation procedures shall be implemented. Primary, redundancy from hardware and data backup from software/data point of view must be in place. 6/18/2024 503 Version: 5.19::4 Appendix G - Threat Register Tampering with Tabulator System Availability • Description: Prior or during the voting phase, voting devices become inoperable or not capable of processing ballots. • Threat: The attacker can either perform physical destruction (in a warehouse or in transit) or logical destruction (install malicious software on the machine) of the device causing a denial of service type of an attack. Logical destruction of the device could not only cause the alteration of election data including votes), but could also cause a slow down of the system operation. • Impact: System becomes unavailable for voting. • Impacted Security Pillars: Data integrity, access control, availability. • Risk Rating: Medium. • Mitigation: Proper physical security controls prevent the physical destruction of the voting equipment, while the proper software security measures (code signing, data signing and encryption) prevent the attacker from breaking into the device and making it inoperable for election event. Tampering with Ballot Secrecy • Description: Attacker influences how voters will vote by breaking the ballot secrecy. • Threat: The attacker is usually unable to influence voting directly, but might still be able to determine how individuals or groups voted. The attacker might engage in either vote buying or information gathering.In a vote buying attack, the attacker pays or threatens individual voters to vote in a specific way. In order for this attack to be successful, the attacker needs to be able to verify how the voter voted. NOTE: The attacker does not need to be absolutely certain how the voter voted they must only make the voter believe that the voters vote has a good chance of being verified. • Impact: Attacker can achieve a limited success and influence on the election results. • Impacted Security Pillars: Privacy, Confidentiality. • Risk Rating: Medium. • Mitigation: By implementing advanced ballot security mechanisms and by following the best information security practices, including the education of personnel and voters, the scope of this type of an attack can be drastically minimized. If voters and jurisdiction have sufficient knowledge about the system as well as trust in the security controls implemented into the system, an attacker will have a difficult task to influence how voters vote. If the external enclosures of the servers you receive allow for tamper-evident 6/18/2024 504 Version: 5.19::4 Appendix G - Threat Register sealing via a hasp, utilize a “redwire” or lock style tamper-evident seal to provide tamper evidence over intrusion into the workstation chassis. A lock is another possibility when the server has hasps.If no hasps are present, examine the server’s enclosure and chassis to determine places where these separate when the server is opened. Apply two or more tamper evident seals, prefer ably at points opposite to one another on the workstation chassis to provide tamper evidence of the workstation being opened. 6/18/2024 505 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components APPENDIX H: PHYSICAL SECURITY OF DEMOCRACY SUITE® SYSTEM AND COMPONENTS ® The Democracy Suite System and all of its components must be physically secured in a locked area with security access controls in place. No access to this area should be permitted to unauthorized personnel. The jurisdiction must provide a secure physical and procedural environment for the storage, handling, preparation, and transportation of the system hardware. Procedural and physical controls for ballot boxes and ballot handling in a central scanning application scenario should be done in accordance with jurisdiction's and State requirements. H.1 Re-Zero Results Using the Advanced Admin Option Figure H-1: Re-zero Results 1. If the election cards have been used for testing prior to the election day (during Logic and Accuracy testing procedure) then all the recorded results need to be set to zero. 2. On the poll worker Menu screen, press the Advanced Admin option. Re-zero Results menu will appear in the right-side of the screen. 3. Depending on the configuration set in the MBS file, you may be asked to provide a username and password, password only when entering the Advanced Admin menu. In addition, the MBS gives an option to omit the authentication. Next, Re-zero Results menu appears. Press Re-zero button. 6/18/2024 506 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components 4. When prompted, enter the credentials (the poll worker's credentials are set in EMS EED client application). 5. The Confirmation screen will appear asking for the confirmation to set the results to zero. Press OK to proceed. Figure H-2: Confirmation Dialog 6/18/2024 507 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components 6. Finally, Poll-Worker main screen will be presented. On the activity bar, the Ballot Counter indicates that the results are zero. Figure H-3: Figure H.2 Physical Security ® The physical security on the Democracy Suite system and its components is supplemented by security seals that are applied as summarized in the table below. 6/18/2024 508 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components NOTE: The brand, type, and color of all seals may vary. Seals should be evaluated for functionality prior to deployment. Color Purpose White self-adhesive enclosure seals ® Applied on the ImageCast Evolution 's CF0 door in the warehouse and left intact by the poll worker. Also used on workstations. White or Red wire seals on the ballot ® Two are applied on the ImageCast box Evolution latch, and two on the ballot box lid latch. Semi-permanent/not broken. Red padlock seal To remain on the system and components throughout the election cycle. Yellow padlock seal To be removed by the poll worker once the polls are closed, or as required, in order to remove CF cards. Green padlock seal To be removed by the poll worker to remove the ballot box cover. Table H-1: Physical Security — Types of Seals H.3 Plastic Ballot Box Physical Security The plastic ballot box is physically secured by seven color-coded security seals, and five locks. Ballot Box Security Seals Quantity Color Location 3 Yellow Primary Compartment Door, Secondary Compartment Door, Auxiliary Compartment Slot 2 Green Front of the ballot box lid, back of the ballot box lid 2 Red/White Tabulator latches Table H-2: Physical Security — Ballot Box Security Seals 6/18/2024 509 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components Ballot Box Security Locks Quantity Location 2 Each side of the ballot box lid 1 Auxiliary Compartment Slot 1 Primary Compartment Door 1 Secondary Compartment Door Table H-3: Physical Security — Ballot Box Security Locks 6/18/2024 510 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components The following figures shows the location of the Green security seal on the front of the ballot box lid, the Yellow security seal on the Primary Compartment Door, and the locations of two locks – one on the side of the Ballot Box Lid, and one on the Primary Compartment Door. Figure H-4: Figure 6/18/2024 511 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components Next figure illustrates Security Seals applied on the inside of the auxiliary bin. Figure H-5: Figure In addition, two white wire seals are applied to the ballot box lid latches. Ballot Box Lid Latches Quantity Color Location 2 White wire seals Ballot box lid latch Table H-4: Physical Security — Ballot Box Lid Latches The following figures illustrates the location of the white wire seals that are applied to the internal latches that lock the lid of the ballot box to the ballot box 6/18/2024 512 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components bin. Figure H-6: Figure H.4 ImageCast® Evolution Physical Security The following figure shows the location of the Yellow security seals on the CF1 Door and Thermal Printer Compartment Door, and the Red security seals on the CF2 Door, Ports Door, Internal Printer Door. ® Figure H-7: The ImageCast Evolution is physically secured by five color-coded 6/18/2024 513 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components security seals. ® ImageCast Evolution Security Seals Quantity Color Location 2 Yellow CF1 Door, Thermal Printer Compartment Door 3 Red CF2 Door, Ports Door, Internal Printer Door ® Table H-5: Physical Security — ImageCast Evolution Security Seals 6/18/2024 514 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components NOTE: Some jurisdictions may wish to remove the CF2 card from the CF2 door upon close of polls. In this case, the CF2 Door should be tagged in yellow. ® ImageCast Evolution Security Seals Quantity Color Location 1 White self-adhesive seal CF0 Door ® Table H-6: Physical Security — ImageCast Evolution Security Seals ® The following image (ImageCast Evolution and Security Seals) depicts the location of the white self-adhesive seal that is applied over top of the CF0 door. The CF0 door is located behind security plating and below the CF1 and CF2 doors. This seal is applied once in the warehouse after the initial firmware installation and is not removed. ® All gaps between the ImageCast Evolution's doors and main shell are minimized to prevent access. Each CF card door audibly clicks into place to confirm that it has been fully closed. To open the door, a thumb clasp is actuated on the left edge of the door. Locking mechanisms deploy hasp-type mechanisms. The metal loop is mounted to an internal metal component.When the door closes, loop provides a location to attach the security seals. Figure H-8: Figure H.5 ImageCast® Central Physical Security Procedural and physical controls for ballot boxes and ballot handling in a central scanning application scenario must be done in accordance with jurisdiction's and State requirements. 6/18/2024 515 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components ® Seal the external enclosures of the ImageCast Central All-in-One workstation with tamper evident self-adhesive security seals, as seen in the following image. Figure H-9: Figure Examine the workstation's enclosure and chassis to determine places where these separate when the workstation is opened. Apply two or more tamper evident seals, preferably at points opposite to one another on the All-in-One to provide tamper evidence of the workstation being opened. H.6 ImageCast® Precinct 2 Physical Security Physical controls incorporate tamper evident seals that limit and detect unauthorized access to the ImageCast Precinct 2 tabulator. Election officials are free to use any tamper evident label or tamper evident tie wrap supplier. There are three (3) locations on the ImageCast Precinct 2 tabulator where security seals are placed: • Memory card access ports • Thermal report printer door • Modem port For securing the ballot box, apply tamper seals between the ballot box and tabulator. 6/18/2024 516 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components H.6.1 Sealing Administrator and Poll Worker Memory Card Access Ports Place a security seal on the Administrator and Poll Work doors' lock loop as seen in the figure below. In this example, a red security seal is used. The doors remain locked during the entire deployment and through Election Day and night.. Figure H-10: Sealing the memory card access doors 6/18/2024 517 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components H.6.2 Sealing the Thermal Report Printer Door Apply a security seal to the thermal printer compartment as seen in the figure below. In this example, a red seal is used. This protects against unauthorized access to this compartment. Figure H-11: Sealing the thermal report printer door 6/18/2024 518 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components H.6.3 Sealing the Modem Port Apply a security seal to the access cover protecting the modem port as seen in the figure below. In this example, a red security seal is used.This protects against unauthorized access to modem components. The access cover remains sealed during deployment and during Election Day. Only poll workers are authorized to break this seal prior to transmit election results. Figure H-12: Sealing the modem port ® All gaps between the ImageCast Precinct 2’s doors and main shell are minimized to prevent access. Each SD card door audibly clicks into place to confirm that it has been fully closed. To open the door, a thumb clasp is actuated on the left edge of the door. Locking mechanisms deploy hasp-type mechanisms. The metal loop is mounted to an internal metal component.When the door closes, loop provides a location to attach the security seals. H.7 Re-zeroing the ICP2 For details on re-zeroing the ICP2, refer to 4.5.8“Re-zeroing the ICP2”. H.8 EMS Server and Workstation Physical Security ® The Democracy Suite EMS environment must be physically secured in a locked area with security access controls in place. No access to this area should be permitted to unauthorized personnel. Your State Election Authority may require that an access control system is utilized that will automatically log and record each individual's access to the EMS Data center environment. Such systems include the use of electronic passes or biometrics to gain entry into the secure area. In addition, if cameras and/or card-key system are not in use, all personnel must be ® required to sign in and out when accessing the secure Democracy Suite EMS environment area. The access log should, at a minimum, include such items as: • Name • Organization 6/18/2024 519 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components • Purpose of access • Date • Time in • Time out 6/18/2024 520 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components • Signature Seal the external enclosures of the EMS laptop workstation with tamper evident self-adhesive security seals, as seen in the following figures. Examine the workstation's enclosure and chassis to determine places where these separate when the workstation is opened. Apply two or more tamper evident seals, preferably at points opposite to one another on the workstation to provide tamper evidence of the workstation being opened. 6/18/2024 521 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components Figure H-13: Figure Figure H-14: Figure All server components of the EMS Data center back-end system have built-in intrusion detection systems. On one side, the server chassis has an intrusion switch, which is connected to a motherboard intrusion jumper (two-wire interface). The intrusion alarm is activated if the chassis cover is open and recorded by the supported server monitoring application. 6/18/2024 522 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components NOTE: If the laptop is equipped with laptop lock functionality, you may use third party locks to secure the workstation to a desk. It is recommended that locks are evaluated for functionality prior to deployment. Figure H-15: Figure H.9 ImageCast® X Physical Security ® ImageCast X is equipped with two security latches that must be secured using plastic security seals in addition to adhesive anti-tamper seals. Use seals (color of your choice - in this example we are using blue seals) for sealing top and bottom trap doors. ® In the case of the ImageCast X Prime device, 4 Plastic pull-up/pull tight seals are used to fasten the 4 doors on the back sides of the device enclosure. NOTE: Ensure all wires required are plugged in properly before sealing. 6/18/2024 523 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components Figure H-16: Top security latch plastic sea 6/18/2024 524 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components l Figure H-17: Bottom security latch plastic seal Figure H-18: Evidence of tampering adhesive seal 6/18/2024 525 Version: 5.19::4 Appendix H - Physical Security of Democracy Suite® System and Components H.10 Reset the Number of Printed Ballots on ImageCast® X 1. Ensure the device is on. 2. Log in Using a poll worker Smart Card. 3. Ensure the poll is closed. If the poll is not closed, select Close Poll. 4. Next to Public Counter select ReZero. H.11 Clear All Election Data on ImageCast® X This option removes all election data from the machine. Returns the machine to factory default settings making it ready for the next election. To clear the election data: 1. Insert the Technician smart card and appropriate PIN. 2. Press Clear All Election Data. The following is removed: • Result files from all defined locations, if they exist. If not all locations are accessible, an appropriate message will be presented. • Audit log files from all result locations, but the last ten audit logs on the device remain, so that there is evidence of clearing election data. • Report file, if it exists. • Election file (.DAT file). • Vote sim (Test deck file). 6/18/2024 526 Version: 5.19::4 Appendix I - Permanent Printed Reports APPENDIX I: PERMANENT PRINTED REPORTS ® The following sections outline the reports generated on the ImageCast Evolution thermal printer. I.1 Diagnostics Report During diagnostics, the printer produces a record of each test performed by the user. It also provides the ability to produce multiple records. I.2 Zero Report The zero report is a results report that shows that there are no ballots yet cast in the election. The report: • Lists the name and details of the election, • Lists the date and time when the report was generated, • Lists all of the candidates and their vote totals, by contest, ballot, or by precinct. The LCD offers the option to print additional copies of the report to ensure that the user receives a successful copy. Please note that the default number of precincts on a zero report is set to twenty five. However, this value can be decreased within the DCF or MBS file should the election content breach the length of a roll of thermal printer paper. Should the printer roll deplete during printing: 1. Change the printer roll. 2. Press Resume on the LCD screen. The printer will: • Print a line indicating that the printer was interrupted. • Re-print the Zero Report's header. • Print a line indicating that the report is continuing on a new 'Tape Section'. Resume printing the report from approximately two lines prior to the previous roll’s depletion. I.3 Interrupt Report If any sort of failure occurs (such as power or other errors), the device can be returned to the same operating condition that existed immediately prior to the error or failure without loss or corruption to the voting data stored in the device. The interrupt report is generated when the unit is powered up successfully with processed ballots.The report: 6/18/2024 527 Version: 5.19::4 Appendix I - Permanent Printed Reports • Lists the name and details of the election • Lists the date and time when the report was generated • Total number of ballots processed There is no information reported about any contest as the poll has not yet been closed. The LCD offers the option to print additional copies of the report to ensure that the user receives a successful copy. I.4 Results Report The results report is generated when the 'Poll Close' action is selected. The report contains: • Name and details of the election. • Date and time of when the report was generated. • The order of candidates as they appear on the results tape, which is set in the DCF or MBS options via EMS. Candidates listed on the reports can either be listed by the number of votes for each candidate in each contest, by precinct, or by the ballot order (i.e. in the same order as they appear on the ballot). • Election totals Should the printer roll deplete during printing: 1. Change the printer roll by following the steps outlined in section Changing the Printer Paper Tape (refer to “6.4.1.10Changing the Printer Paper Tape”). 2. Press Resume on the LCD screen. 3. The printer will: • Print a line indicating that the printer was interrupted. • Re-print the Result Report's header. • Print a line indicating that the report is continuing on a new 'Tape Section'. • Resume printing the report from approximately two lines prior to the previous roll’s depletion. • The LCD offers the option to print additional copies of the report to ensure that the user receives a successful copy. I.5 Status Report The election statistics report contains the following: • Tabulator Name • Tabulator ID 6/18/2024 528 Version: 5.19::4 Appendix I - Permanent Printed Reports • Voting Location • Precinct Number • Total Ballots Scanned • Total Voters • Unit Model • Unit Serial Number • Software Version 6/18/2024 529 Version: 5.19::4 Appendix J - Certified Firmware APPENDIX J: CERTIFIED FIRMWARE J.1 Democracy Suite EMS Certified Versions Application Version EMS Adjudication Client TBD EMS Application Server TBD EMS Audio Studio TBD EMS Election Data Translator TBD EMS Election Event Designer TBD EMS File System Service TBD EMS ImageCast Central TBD EMS ImageCast Voter Activation TBD EMS Logger TBD EMS RTM TBD EMS Results Tally and Reporting TBD EMS Smart Card Helper Service TBD Table J-1: Democracy Suite EMS Certified Versions J.2 ImageCast Tabulator & BMD Certified Firmware Versions Product Version ImageCast ICX TBD ImageCast ICP TBD ImageCast ICP 2 TBD Canon G1130 V1 1.33 Canon G2140 1.23 Canon X10C 2.80 6/18/2024 530 Version: 5.19::4 Appendix J - Certified Firmware Table J-2: ImageCast Tabulator & BMD Certified Firmware Versions 6/18/2024 531 Version: 5.19::4 Appendix K - BIOS Settings Quick Reference APPENDIX K: BIOS SETTINGS QUICK REFERENCE K.1 EMS Standard Server (PowerEdge R660) 1. System BIOS > Restore Defaults a. Boot Settings > Boot Mode > UEFI b. Boot Settings > Boot Option Enable/Disable > Disable DVD and NIC c. Boot Settings >Boot Sequence > Move C: to top of list d. SATA Settings > AHCI e. System Security > Secure Boot > Enabled f. Integrated Devices > iDRAC Direct USB Port > Set to Off g. Serial Communication > Set Serial Communication to Off h. Network Settings > Disable ALL PXE devices i. System Security > Apply Setup Password 2. iDRAC Settings a. Network • Enable NIC = Enabled • Common Settings > Disabled • IPV4 Settings > Disabled • IPV6 Settings > Disabled 6/18/2024 532 Version: 5.19::4 Appendix K - BIOS Settings Quick Reference K.2 BIOS EMS Client/ADJ Client (Precision 3460) 1. Restore Settings > BIOS defaults 2. Reboot 3. General a. Boot Sequence > UEFI b. Advanced Boot Options > Enable Legacy Option ROMS = Unchecked c. Date/Time > Set 4. System Configuration a. SATA Operation > AHCI b. SMART Reporting > Enable SMART Reporting = Enabled 5. Secure Boot a. Secure Boot Enable > Enabled 6. Wireless a. Wireless Switch • Uncheck (disable) all devices b. Wireless Device Enable • Uncheck (disable) all devices 7. System Configuration >USB Configuration > Uncheck Enable Boot Support 6/18/2024 533 Version: 5.19::4 Appendix K - BIOS Settings Quick Reference K.3 ICC (OptiPlex 7440 AIO/5270 AIO), ICVA (Latitude 3410/3400), RTM (Latitude 3400) 1. Restore Settings > BIOS defaults 2. Reboot 3. General a. Boot Sequence > UEFI b. Advanced Boot Options > Enable Legacy Option ROMS = Unchecked c. Date/Time > Set 4. System Configuration a. SATA Operation > AHCI b. SMART Reporting > Enable SMART Reporting = Checked c. Miscellaneous Devices > Enable Camera = Unchecked 5. Secure Boot a. Secure Boot Enable > Enabled 6. Wireless (for RTM laptops only wireless is enabled) a. Wireless Switch • Uncheck (disable) all devices b. Wireless Device Enable • Uncheck (disable) all devices 6/18/2024 534 Version: 5.19::4 Appendix K - BIOS Settings Quick Reference K.4 Configure BIOS (Admin) password (Windows 11 Computers) NOTE: The County’s computers should already have a BIOS (Admin) password set. Only perform the steps if the password is not set, or if the County wants to change their password. 1. While in the BIOS setup screen, expand the Security submenu. 2. Select Admin Password (not the System Password). 3. Set a password (defined by the county). NOTE: The recommendation is at least 8 characters with a combination of uppercase and lowercase letters and at least one number and one special character 4. Click OK. 5. Ensure that the password has been recorded and kept in a safe place. 6. Click Exit to restart the computer. K.5 Disable boot from USB (Windows 11 Computers) 1. Turn on the computer (or reboot, if already powered on). 2. During boot, press F2 to enter the Setup menu. 3. In the Setup menu, click Unlock. 4. Enter the Admin password. 5. Expand the System Configuration Menu. 6. Select USB Configuration. 7. Uncheck the Enable Boot Support checkbox. 8. Click Apply. 6/18/2024 535 Version: 5.19::4 Democracy Suite® Use Procedures APPENDIX L: BITLOCKER ENCRYPTION L.1 Enabling BitLocker to EMS Client and Express Systems Using Bit Locker encryption improves the security of the workstation. BitLocker offers an encryption using Trusted Platform Module (TPM) chip. To turn off device encryption: 1. Click Start and search for Settings. 2. Click Settings and then select Privacy & Security. 3. If available, select Device Encryption and then set device encryption to Off. L.2 Enabling BitLocker Using Trusted Platform Module (TPM) to Client and Express Systems To check if a computer has TPM on Windows 11: 1. Click Start and search for Device Manager. 2. Click Device Manager to open the application. 3. Expand Security Devices. 4. Confirm that the node titled Trusted Platform Module followed by a version number exists. NOTE: Before any action, a blank USB flash drive should be connected to the workstation. If you have a TPM device embedded in your hardware, follow these steps to enable BitLocker: 1. Right click Start, then select Run. 2. In the run window, type gpedit.msc. 3. Navigate to: Computer Configuration -> Administrative Templates -> Windows Components -> Bitlocker Drive Encryption -> Operating System Drives -> Require additional authentication at startup. 4. Change the "Configure TPM Startup PIN" option to "Allow startup PIN with TPM". 6/18/2024 536 Version: 5.19::4 Democracy Suite® Use Procedures 5. Change the "Configure TPM Startup Key and PIN" option to "Allow startup Key and PIN with TPM". 6. Click OK and restart the computer. 7. Once the computer restarts, click Start and search for Control Panel. 8. Click Control Panel to open the application. 9. Click System and Security. 10. Click BitLocker Drive Encryption. 11. In the ‘Operating system drive’ section, click Turn on BitLocker. 12. Select Enter. 13. When prompted, select the Enter Pin option. Click Next. 14. Select Save the Recovery Key. 15. Save the file to your USB removable medium. NOTE: Keep this USB removable medium in a secure location. Everyone who has this file can access the disk drive. 16. Click Next. 17. In the ‘Choose between two encryption options’ section, select Encrypt the entire drive. This may take some time. 18. Click Next. 19. In the ‘Choose between the two-encryption options’ section, select New encryption mode. 20. Click Next. 21. Select Run BitLocker system. 22. Click Continue. 23. Click Restart. BitLocker will now be enabled, and you will now be prompted to enter an encryption pin to continue starting Windows 10. BitLocker will continue to encrypt in the drive. This process can take a long time, but can be left running in the background as you work. 6/18/2024 537 Version: 5.19::4 ® Democracy Suite Use Procedures REVISION HISTORY Rev. Date Summary 4 06-18-2024 Removed Avision content 3 06-17-2024 Added section Reporting Troubleshooting 2 05-21-2024 • Revised Appendices with updated procedures. • Revised Chapter 3 System Installation and Configuration with updated procedures. • Updated components lists for section 3.1 Hardware Requirements and Specifications. • Added Sections, Encrypting an Election Project, and, Exporting an Encryption Certificate, to Chapter 12. • Revised Chapter 3 System Installation and Configuration with updated procedures. • Updated Chapter 9 Adjudication with grammar and content corrections. 1 10-10-2023 Branched for 5.19 6/18/2024 538 Version: 5.19::4 ® Democracy Suite Use Procedures LIST OF FIGURES ® Figure 1-1: ImageCast Evolution. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 ® Figure 1-2: 5.19 ImageCast Central (ICC) G2140 . . . . . . . . . . . . . . . . . . . . 3 ® Figure 1-3: ImageCast Precinct 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 Figure 1-4: EMS Workstation and EMS Server. . . . . . . . . . . . . . . . . . . . . . . . 6 ® Figure 1-5: ImageCast X . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 Figure 3-1: EMS/RTR Air-gap Network Configuration. . . . . . . . . . . . . . . . . 28 Figure 3-2: EMS/EED Air-gap Network Configuration. . . . . . . . . . . . . . . . . 29 Figure 3-3: Air-gap Isolation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29 Figure 3-4: Adding a language pack. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 91 Figure 3-5: Adding Localization File. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 93 Figure 3-6: Adding Static Audio Folder. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 94 Figure 3-7: Adding Language Audio File. . . . . . . . . . . . . . . . . . . . . . . . . . . . 95 Figure 3-8: EED Language Profile window. . . . . . . . . . . . . . . . . . . . . . . . . . 96 ® Figure 3-9: ImageCast Precinct 2 Ballot Counter . . . . . . . . . . . . . . . . . . . 104 Figure 4-1: USB Drive containing Election Files and the Copy/Cancel Election Files Dia- log. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 159 Figure 4-2: ICC Configure screen - Close option. . . . . . . . . . . . . . . . . . . . . 168 Figure 4-3: ICC Configure screen - Confirm Close Tabulator. . . . . . . . . . . 168 Figure 4-4: ICC Supervisor Mode Password screen. . . . . . . . . . . . . . . . . . . 169 Figure 4-5: ICC Supervisor Mode Configure screen - Re-Zero Results . . . 170 Figure 4-6: Re-zero Results Confirmation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .171 Figure 4-7: Main Menu screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 172 Figure 4-8: Poll Management screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173 Figure 4-9: Re-Zero Confirmation screen . . . . . . . . . . . . . . . . . . . . . . . . . . 173 Figure 4-10: ICX - Re-zero option on Poll Administration screen. . . . . . . . 174 Figure 6-1: LCD Monitor in Operating Position . . . . . . . . . . . . . . . . . . . . . 191 Figure 6-2: Position the tabulator on top of the ballot box. . . . . . . . . . . . . . 193 Figure 6-3: Connect the round end of the AC to DC power adapter Route the power adapter cord to the side of the ballot box, as shown in Figure 6-4.194 Figure 6-4: Route the power adapter cord to the side. . . . . . . . . . . . . . . . . . 194 Figure 6-5: Ready screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 196 6/18/2024 539 Version: 5.19::4 List of Figures Figure 6-6: Sealing Administrator and Poll Worker Memory Card Access Ports197 Figure 6-7: Sealing the Thermal Report Printer Door . . . . . . . . . . . . . . . . . 197 Figure 6-8: Sealing the Modem Port. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 198 Figure 6-9: Ballot Review screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 198 Figure 6-10: Ballot Review screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 199 Figure 6-11: Review Complete screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 199 Figure 6-12: Evidence of Tampering: Peeled Label. . . . . . . . . . . . . . . . . . . 202 Figure 6-13: Evidence of Tampering: Peeled and Reapplied. . . . . . . . . . . . 202 Figure 6-14: Top aValue security latch seal. . . . . . . . . . . . . . . . . . . . . . . . . 203 Figure 6-15: Bottom aValue security latch seal . . . . . . . . . . . . . . . . . . . . . . 203 Figure 6-16: Green Ballot Box Seals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 205 ® Figure 6-17: ImageCast Evolution Seals. . . . . . . . . . . . . . . . . . . . . . . . . . 206 ® Figure 6-18: ImageCast Evolution Power Source. . . . . . . . . . . . . . . . . . . 206 ® Figure 6-19: Lifting the LCD Screen on the ImageCast Evolution. . . . . . 207 Figure 6-20: iButton Security Key Prompt. . . . . . . . . . . . . . . . . . . . . . . . . . 207 Figure 6-21: Main Menu. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 209 Figure 6-22: Number of Zero Tape Copies to Print . . . . . . . . . . . . . . . . . . . 209 Figure 6-23: Open button in the Main Menu . . . . . . . . . . . . . . . . . . . . . . . . 210 Figure 6-24: Printing of Zero Tapes in Progress . . . . . . . . . . . . . . . . . . . . . 210 Figure 6-25: Printing of Zero Tape Completed . . . . . . . . . . . . . . . . . . . . . . 211 Figure 6-26: Poll Ready for Operation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 211 Figure 6-27: Sample Ballot. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 212 Figure 6-28: Enter password. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 213 Figure 6-29: Password correct . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 213 Figure 6-30: Main Menu screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 214 Figure 6-31: Poll Management screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 214 Figure 6-32: Open Poll Confirmation screen . . . . . . . . . . . . . . . . . . . . . . . . 215 Figure 6-33: Printing in Progress screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . 215 Figure 6-34: Please Insert Ballot screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . 216 Figure 6-35: Main Menu screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 217 Figure 6-36: Utilities screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 217 Figure 6-37: Tabulator Info screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 218 Version: 5.19::4 540 6/18/2024 List of Figures Figure 6-38: Tabulator Info screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 218 Figure 6-39: Verification Messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 220 Figure 6-40: Time out for Inserting Ballot. . . . . . . . . . . . . . . . . . . . . . . . . . 221 Figure 6-41: Ballot Review. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 221 Figure 6-42: Cast Ballot Confirmation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 222 Figure 6-43: Multi-card Session Continuation. . . . . . . . . . . . . . . . . . . . . . . 223 Figure 6-44: Session is Complete. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 223 Figure 6-45: Ballot Already Inserted . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 224 Figure 6-46: Standard Voting - System Ready Screen. . . . . . . . . . . . . . . . . 224 Figure 6-47: Overvote Ballot Review Screen. . . . . . . . . . . . . . . . . . . . . . . . 225 Figure 6-48: Overvote Error Screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 225 Figure 6-49: Remove Ballot from the Device Screen. . . . . . . . . . . . . . . . . . 226 Figure 6-50: Undervote Ballot Review Screen. . . . . . . . . . . . . . . . . . . . . . . 226 Figure 6-51: Ambiguous Mark Ballot Review Screen. . . . . . . . . . . . . . . . . 227 Figure 6-52: Ambiguous Mark Error Screen.. . . . . . . . . . . . . . . . . . . . . . . . 227 Figure 6-53: Valid Ballot Review Screen. . . . . . . . . . . . . . . . . . . . . . . . . . . 228 Figure 6-54: Lever in Head Up/Down Position . . . . . . . . . . . . . . . . . . . . . . 229 Figure 6-55: Paper Roll Installed . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 230 Figure 6-56: Scanning Ballot screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 231 Figure 6-57: Ballot Successfully Cast screen. . . . . . . . . . . . . . . . . . . . . . . . 232 Figure 6-58: Action Bar . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 241 Figure 6-59: Contest Stripe. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 241 Figure 6-60: Stripe . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 242 Figure 6-61: Navigation Bar. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 242 Figure 6-62: Poll Worker Main Menu screen. . . . . . . . . . . . . . . . . . . . . . . . 244 Figure 6-63: Poll Management - Accessible Voting Session. . . . . . . . . . . . 245 Figure 6-64: Welcome to Your Voting Session . . . . . . . . . . . . . . . . . . . . . . 246 Figure 6-65: AVS - Language Selection. . . . . . . . . . . . . . . . . . . . . . . . . . . . 246 Figure 6-66: AVS - Device Selection screen . . . . . . . . . . . . . . . . . . . . . . . . 247 Figure 6-67: AVS - ATI Instructions screen . . . . . . . . . . . . . . . . . . . . . . . . 248 Figure 6-68: AVS - Paddles Instructions Screen . . . . . . . . . . . . . . . . . . . . . 249 Figure 6-69: AVS - Sip-and-Puff Instructions Screen . . . . . . . . . . . . . . . . . 250 Version: 5.19::4 541 6/18/2024 List of Figures Figure 6-70: AVS - Display On Selection Screen . . . . . . . . . . . . . . . . . . . . 250 Figure 6-71: AVS - Audio Only Selection Screen. . . . . . . . . . . . . . . . . . . . 251 Figure 6-72: AVS - Audio Only Screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . 252 Figure 6-73: AVS - Voting Screen Sections . . . . . . . . . . . . . . . . . . . . . . . . 253 Figure 6-74: AVS - Voting Screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 254 Figure 6-75: AVS - Write In Screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 255 Figure 6-76: AVS - Ballot Review. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 256 Figure 6-77: AVS - Ballot Printing in Progress . . . . . . . . . . . . . . . . . . . . . . 257 Figure 6-78: AVS - Ballot Casting. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 258 Figure 6-79: AVS - Ballot Casting Confirmation. . . . . . . . . . . . . . . . . . . . . 258 Figure 6-80: AVS - Ballot Casting. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 259 Figure 6-81: AVS- Session Continuation. . . . . . . . . . . . . . . . . . . . . . . . . . . 260 Figure 6-82: ICX - Accessible Voting Start screen . . . . . . . . . . . . . . . . . . . 261 Figure 6-83: ICX - Privacy Mask Selection screen . . . . . . . . . . . . . . . . . . . 262 Figure 6-84: ATI Usage Instructions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 263 Figure 6-85: Audio options menu. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 264 Figure 6-86: Enabling Provisional Voting . . . . . . . . . . . . . . . . . . . . . . . . . . 268 Figure 6-87: Poll Worker Menu . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 269 Figure 6-88: Close Poll - Authorization Screen . . . . . . . . . . . . . . . . . . . . . . 270 Figure 6-89: Close Poll Confirmation Screen. . . . . . . . . . . . . . . . . . . . . . . . 270 Figure 6-90: Auxiliary Bin Prompt . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 271 Figure 6-91: Printing of Result Tape Completed . . . . . . . . . . . . . . . . . . . . . 271 Figure 6-92: Poll-Worker Menu once Polls have been Closed . . . . . . . . . . 272 Figure 6-93: Power Down Request. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 273 Figure 6-94: Breaking the Ballot Box Seal. . . . . . . . . . . . . . . . . . . . . . . . . . 273 Figure 6-95: Removing Ballots from the Ballot Box. . . . . . . . . . . . . . . . . . 274 Figure 6-96: Removing the CF1 Card . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 274 Figure 6-97: Main Menu screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 275 Figure 6-98: Poll Management screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 276 Figure 6-99: Results Report screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 276 Figure 6-100: Enter Number of Copies screen. . . . . . . . . . . . . . . . . . . . . . . 277 Figure 6-101: Write-in Report screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 277 Version: 5.19::4 542 6/18/2024 List of Figures Figure 6-102: Write-in Report screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 278 Figure 6-103: Enter Number of Copies screen. . . . . . . . . . . . . . . . . . . . . . . 278 Figure 6-104: Close Poll Confirmation screen. . . . . . . . . . . . . . . . . . . . . . . 278 Figure 6-105: Printing in Progress screen. . . . . . . . . . . . . . . . . . . . . . . . . . . 279 Figure 6-106: Printing Completed screen. . . . . . . . . . . . . . . . . . . . . . . . . . . 279 Figure 6-107: Printing in Progress screen. . . . . . . . . . . . . . . . . . . . . . . . . . . 280 Figure 6-108: Printing Completed screen. . . . . . . . . . . . . . . . . . . . . . . . . . . 280 Figure 6-109: Main Menu screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 281 Figure 6-110: Power Options screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 282 Figure 6-111: Power Down screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 282 Figure 6-112: Breaking the Ballot Box Seal. . . . . . . . . . . . . . . . . . . . . . . . . 283 Figure 6-113: Removing Ballots from the Ballot Box. . . . . . . . . . . . . . . . . 283 Figure 6-114: Internal Battery with Connectors. . . . . . . . . . . . . . . . . . . . . . 286 Figure 7-1: ICC - Main Scan Screen - Review option . . . . . . . . . . . . . . . . . 289 Figure 7-2: ICC Review Screen - Select All and Export . . . . . . . . . . . . . . . 290 Figure 7-3: ICC - Confirmation Dialog . . . . . . . . . . . . . . . . . . . . . . . . . . . . 290 Figure 7-4: ICC - Browse and Select Folder . . . . . . . . . . . . . . . . . . . . . . . . 291 Figure 7-5: ICC - Export Batches Confirmation Dialog. . . . . . . . . . . . . . . . 291 Figure 7-6: ICC - Add New . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 293 Figure 7-7: ICC - Browse to the location of Election Files . . . . . . . . . . . . . 294 Figure 7-8: ICC - Enter Tabulator Name . . . . . . . . . . . . . . . . . . . . . . . . . . . 295 Figure 7-9: ICC - Add New Tabulator Confirmation Dialog. . . . . . . . . . . . 295 Figure 7-10: ICC - Please Select a Tabulator Screen. . . . . . . . . . . . . . . . . . 296 Figure 7-11: ICC - Ready to Apply the iButton Security Key. . . . . . . . . . . 296 Figure 7-12: ICC - Enter Password. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 297 Figure 7-13: ICC - Main Scan Screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 297 Figure 7-14: ICC - Click Configure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 298 Figure 7-15: ICC - Click Set New Path . . . . . . . . . . . . . . . . . . . . . . . . . . . . 299 Figure 7-16: ICC - Set Secondary Path Confirmation Dialog . . . . . . . . . . . 299 Figure 7-17: ICC - Select Secondary Path - Select NAS . . . . . . . . . . . . . . . 300 Figure 7-18: ICC - Secondary Path Set - Upload Results is On. . . . . . . . . . 301 Figure 7-19: ICC - Click Configure - After Secondary Path Set . . . . . . . . . 302 Version: 5.19::4 543 6/18/2024 List of Figures Figure 7-20: ICC - Settings - Countback Option . . . . . . . . . . . . . . . . . . . . . 303 Figure 7-21: ICC - Batches Option. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 304 Figure 7-22: ICC - Stop Scan Conditions. . . . . . . . . . . . . . . . . . . . . . . . . . . 304 Figure 7-23: ICC - Ballot Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . 305 Figure 7-24: ICC - Enter Supervisor Mode . . . . . . . . . . . . . . . . . . . . . . . . . 306 Figure 7-25: ICC - Enter Password to Access Supervisor Mode . . . . . . . . . 307 Figure 7-26: ICC - In Supervisor Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . 307 Figure 7-27: ICC - Imprinter Settings - G1130 . . . . . . . . . . . . . . . . . . . . . . 309 Figure 7-28: ICC - Imprinter Setting - InoTec - Pre-Imprinter . . . . . . . . . . 311 Figure 7-29: ICC - Imprinter Setting - InoTec HiPro Scanner- Post-Imprinter312 Figure 7-30: ICC - Main Scan Screen - Zero Results. . . . . . . . . . . . . . . . . . 313 Figure 7-31: ICC - Review Screen - Zero Batches - Click Create Report . . 313 Figure 7-32: ICC - Create Report Screen - No Options Set. . . . . . . . . . . . . 314 Figure 7-33: ICC - Enter Header Text for Zero Report . . . . . . . . . . . . . . . . 314 Figure 7-34: ICC - Select Report Type - Zero and Status . . . . . . . . . . . . . . 315 Figure 7-35: ICC - Select Report Breakdown . . . . . . . . . . . . . . . . . . . . . . . 316 Figure 7-36: ICC - Zero Report - Parameters Set. . . . . . . . . . . . . . . . . . . . . 316 Figure 7-37: ICC - Zero Report Generated. . . . . . . . . . . . . . . . . . . . . . . . . . 317 Figure 7-38: ICC - Browse to Location to Save File . . . . . . . . . . . . . . . . . . 318 Figure 7-39: ICC - Scanning Mode Screen . . . . . . . . . . . . . . . . . . . . . . . . . 319 Figure 7-40: ICC - Scanning Mode - with iButton. . . . . . . . . . . . . . . . . . . . 320 Figure 7-41: ICC - Scanning Mode - Accept and Discard Options . . . . . . . 321 Figure 7-42: ICC - Accept Batch Prompt. . . . . . . . . . . . . . . . . . . . . . . . . . . 321 Figure 7-43: ICC - Discard Batch Confirmation Dialog . . . . . . . . . . . . . . . 322 Figure 7-44: ICC - Main Scan Screen - Enter Supervisor Mode and click Review323 Figure 7-45: ICC - Select Batch to Spoil . . . . . . . . . . . . . . . . . . . . . . . . . . . 324 Figure 7-46: ICC - Spoil Batches Confirmation Dialog. . . . . . . . . . . . . . . . 324 Figure 7-47: ICC - Batch Spoiled. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 325 Figure 7-48: ICC - Select Batch to Delete . . . . . . . . . . . . . . . . . . . . . . . . . . 326 Figure 7-49: ICC - Delete Batch Confirmation Dialog . . . . . . . . . . . . . . . . 326 Figure 7-50: ICC - Review Button. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 328 Figure 7-51: ICC - Review Screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 329 Version: 5.19::4 544 6/18/2024 List of Figures Figure 7-52: ICC - Status Report Options . . . . . . . . . . . . . . . . . . . . . . . . . . 330 Figure 7-53: ICC - Status Report Generated . . . . . . . . . . . . . . . . . . . . . . . . 331 Figure 7-54: ICC - Click Configure to Close. . . . . . . . . . . . . . . . . . . . . . . . 332 Figure 7-55: ICC - Click Close. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 332 Figure 7-56: ICC - Close Tabulator Dialog . . . . . . . . . . . . . . . . . . . . . . . . . 333 Figure 7-57: ICC - Click Review . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 333 Figure 7-58: ICC - Generate Results Report . . . . . . . . . . . . . . . . . . . . . . . . 334 Figure 7-59: ICC - Results Report Generated . . . . . . . . . . . . . . . . . . . . . . . 335 Figure 8-1: EMS Application Server Settings Screen . . . . . . . . . . . . . . . . . 337 Figure 8-2: Login Screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 338 Figure 8-3: Load Results Dialog. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 340 Figure 8-4: Load Results dialog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 341 Figure 8-5: Load Results dialog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 341 Figure 8-6: Load Results dialog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 342 Figure 8-7: Load Results Dialog. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 342 Figure 8-8: Load Results Dialog. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 343 Figure 8-9: Load Results Dialog. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 343 Figure 8-10: Automatic Result Loading dialog . . . . . . . . . . . . . . . . . . . . . . 345 Figure 8-11: Auto-Reporting Template text files. . . . . . . . . . . . . . . . . . . . . 350 Figure 8-12: Templates in NAS folder on RTR/Tabulation server . . . . . . . 350 Figure 8-13: Results Tally and Reporting - Actions tab. . . . . . . . . . . . . . . . 351 Figure 8-14: SOS Mapping window. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 352 Figure 8-15: SOS Mapping screen- Load Template File . . . . . . . . . . . . . . . 352 Figure 8-16: Operation Success dialog. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 352 Figure 8-17: SOS Mapping screen- Load Mappings . . . . . . . . . . . . . . . . . . 353 Figure 8-18: SOS Mapping screen - Auto Mapping. . . . . . . . . . . . . . . . . . . 353 Figure 8-19: SOS Mapping screen - External Contests . . . . . . . . . . . . . . . . 354 Figure 8-20: SOS Mapping screen - External Contest Name list. . . . . . . . . 354 Figure 8-21: SOS Mapping screen - External Candidate and Linked EMS Candidate lists 354 Figure 8-22: SOS Mapping - Unlinking incorrect object. . . . . . . . . . . . . . . 355 Figure 8-23: SOS Mapping - Linking correct object . . . . . . . . . . . . . . . . . . 355 Figure 8-24: SOS Mapping - Linking Candidates/Choices . . . . . . . . . . . . . 356 Version: 5.19::4 545 6/18/2024 List of Figures Figure 8-25: SOS Mapping - Matching External District Name and Linked EMS District 357 Figure 8-26: SOS Mapping - Add/Change a mapping. . . . . . . . . . . . . . . . . 357 Figure 8-27: SOS Mapping - Create Report. . . . . . . . . . . . . . . . . . . . . . . . . 358 Figure 8-28: Create SOS Report dialog . . . . . . . . . . . . . . . . . . . . . . . . . . . . 358 Figure 8-29: SOS Mapping - Save As dialog. . . . . . . . . . . . . . . . . . . . . . . . 359 Figure 9-1: Adjudication - Access Users Menu . . . . . . . . . . . . . . . . . . . . . . 361 Figure 9-2: Adjudication - List of Existing Users . . . . . . . . . . . . . . . . . . . . 361 Figure 9-3: Adjudication - Create New User . . . . . . . . . . . . . . . . . . . . . . . . 362 Figure 9-4: Adjudication - Create User Settings . . . . . . . . . . . . . . . . . . . . . 363 Figure 9-5: Adjudication - Create User - Click Submit . . . . . . . . . . . . . . . . 363 Figure 9-6: Adjudication - Create User - Temporary Password. . . . . . . . . . 364 Figure 9-7: Adjudication - Users - List of Existing Users to Assign . . . . . . 365 Figure 9-8: Adjudication - Assign Election Event to User. . . . . . . . . . . . . . 365 Figure 9-9: Adjudication - Click Election Events . . . . . . . . . . . . . . . . . . . . 366 Figure 9-10: Adjudication - Assign Users Button . . . . . . . . . . . . . . . . . . . . 366 Figure 9-11: Adjudication - Assign Users to Election Events . . . . . . . . . . . 367 Figure 9-12: Adjudication - Select Adjudication Profile . . . . . . . . . . . . . . . 368 Figure 9-13: Adjudication Profile - Create New . . . . . . . . . . . . . . . . . . . . . 368 Figure 9-14: Adjudication - Create Profile Name . . . . . . . . . . . . . . . . . . . . 369 Figure 9-15: Adjudication - Ballot Filtering & Highlighting Radio Buttons370 Figure 9-16: Adjudication - Create New Profile - Filtering Options . . . . . . 370 Figure 9-17: Adjudication - Write-in Rejection Reasons Screen. . . . . . . . . 372 Figure 9-18: Adjudication - Other Options. . . . . . . . . . . . . . . . . . . . . . . . . . 374 Figure 9-19: Adjudication Profile - Save Profile . . . . . . . . . . . . . . . . . . . . . 375 Figure 9-20: Adjudication - Success Dialog. . . . . . . . . . . . . . . . . . . . . . . . . 375 Figure 9-21: Adjudication - Click Election Events . . . . . . . . . . . . . . . . . . . 376 Figure 9-22: Adjudication - Election Events - Create Adjudication Session376 Figure 9-23: Adjudication - New Session - Click Load Profile . . . . . . . . . . 377 Figure 9-24: Adjudication - Select Profile to Load . . . . . . . . . . . . . . . . . . . 378 Figure 9-25: Adjudication - Basic Data for Loaded Profile. . . . . . . . . . . . . 379 Figure 9-26: Adjudication - New Session - Contest Filtering & Highlighting Options380 Figure 9-27: Adjudication - New Session - Write-in Rejection Reasons. . . 381 Version: 5.19::4 546 6/18/2024 List of Figures Figure 9-28: Adjudication - New Session - Other Options . . . . . . . . . . . . . 382 Figure 9-29: Adjudication - New Session - Summary Screen . . . . . . . . . . . 383 Figure 9-30: Adjudication - New Session - In Progress. . . . . . . . . . . . . . . . 383 Figure 9-31: Adjudication - Administrator Dashboard. . . . . . . . . . . . . . . . . 384 Figure 9-32: Adjudication - Adjudicate Ballots - Click Election Events. . . 384 Figure 9-33: Access Adjudication as Administrator. . . . . . . . . . . . . . . . . . . 385 Figure 9-34: Ballot Adjudication as Administrator . . . . . . . . . . . . . . . . . . . 385 Figure 9-35: Access Adjudication as an Adjudicator. . . . . . . . . . . . . . . . . . 386 Figure 9-36: Ballot Adjudication as Adjudicator . . . . . . . . . . . . . . . . . . . . . 386 Figure 9-37: Floating Overlay Window (Adjudicator View). . . . . . . . . . . . 387 Figure 9-38: Floating Overlay Window (Administrator View) . . . . . . . . . . 388 Figure 9-39: Understanding the Adjudication Screen . . . . . . . . . . . . . . . . . 388 Figure 9-40: Ballot Information Panel - Click History Icon. . . . . . . . . . . . . 389 Figure 9-41: Adjudication History Panel . . . . . . . . . . . . . . . . . . . . . . . . . . . 389 Figure 9-42: Adjudication - Contests Panel . . . . . . . . . . . . . . . . . . . . . . . . . 390 Figure 9-43: Contests Pane - All Contests on Card . . . . . . . . . . . . . . . . . . . 391 Figure 9-44: Click on Quarantine Tab . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 391 Figure 9-45: Quarantine Pane with History . . . . . . . . . . . . . . . . . . . . . . . . . 392 Figure 9-46: Click on History Tab . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 393 Figure 9-47: History Pane with Adjudications. . . . . . . . . . . . . . . . . . . . . . . 394 Figure 9-48: Adjudication - Ballot Navigation Options. . . . . . . . . . . . . . . . 395 Figure 9-49: Adjudication - Ballot Navigation Options Stripe. . . . . . . . . . . 396 Figure 9-50: Front and Back Icons . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 396 Figure 9-51: Adjudication - Ballot Navigation - Front Displayed . . . . . . . . 397 Figure 9-52: Adjudication - Ballot Navigation - Back Displayed . . . . . . . . 397 Figure 9-53: Side-by-Side Icon. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 398 Figure 9-54: Adjudication Ballot Displayed Side-by-Side. . . . . . . . . . . . . . 398 Figure 9-55: Audit Mark Icon. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 398 Figure 9-56: Adjudication - Audit Mark Displayed at Bottom . . . . . . . . . . 399 Figure 9-57: Adjudication - Ballot Navigation - Position Icons. . . . . . . . . . 400 Figure 9-58: Overlay Icon. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 400 Figure 9-59: Adjudication Ballot with Overlay On . . . . . . . . . . . . . . . . . . . 401 Version: 5.19::4 547 6/18/2024 List of Figures Figure 9-60: Adjudication Ballot with Overlay Hidden. . . . . . . . . . . . . . . . 401 Figure 9-61: Close Panel Icon . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 402 Figure 9-62: Contests Panel Collapsed. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 402 Figure 9-63: Contests, Quarantine, and History Icons . . . . . . . . . . . . . . . . . 403 Figure 9-64: Contest Presented for Adjudication with Dotted Red Overlay 403 Figure 9-65: Contest Presented for Adjudication with Solid Red Overlay . 404 Figure 9-66: Contest Displayed with Hover Over Outstack. . . . . . . . . . . . . 404 Figure 9-67: Vote Removed . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 406 Figure 9-68: Vote Added . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 406 Figure 9-69: Click on Write-in Target Area. . . . . . . . . . . . . . . . . . . . . . . . . 407 Figure 9-70: Write-in Resolution Screen 1. . . . . . . . . . . . . . . . . . . . . . . . . . 408 Figure 9-71: Write-in Accept . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 408 Figure 9-72: Write-in Accept to Named Candidate . . . . . . . . . . . . . . . . . . . 409 Figure 9-73: Write-in Reject. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 410 Figure 9-74: Submit and get next button . . . . . . . . . . . . . . . . . . . . . . . . . . . 410 Figure 9-75: Submit and get next - drop-down menu. . . . . . . . . . . . . . . . . . 411 Figure 9-76: Confirm Ballot Save . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 411 Figure 9-77: Access Batch Management . . . . . . . . . . . . . . . . . . . . . . . . . . . 412 Figure 9-78: Batch Management Screen . . . . . . . . . . . . . . . . . . . . . . . . . . . 412 Figure 9-79: Adjudication - Submit Batches . . . . . . . . . . . . . . . . . . . . . . . . 413 Figure 9-80: Submit Batch Confirmation Dialog. . . . . . . . . . . . . . . . . . . . . 413 Figure 9-81: Submit Batch Success Messages . . . . . . . . . . . . . . . . . . . . . . . 414 Figure 9-82: Send batch to readjudicate or review. . . . . . . . . . . . . . . . . . . . 414 Figure 9-83: Change Status Confirmation Dialog . . . . . . . . . . . . . . . . . . . . 415 Figure 10-1: Reports submenu - Results Reporting option . . . . . . . . . . . . . 418 Figure 10-2: Results Reporting Screen - Create Report. . . . . . . . . . . . . . . . 418 Figure 10-3: Precinct Canvass Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 419 Figure 10-4: Reports submenu - Results Reporting option . . . . . . . . . . . . . 420 Figure 10-5: Results Reporting Screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 420 Figure 10-6: Precinct Canvass Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 421 Figure 12-1: Project Parameters - Security Tab . . . . . . . . . . . . . . . . . . . . . . 433 Figure 12-2: Error message dialog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 434 Version: 5.19::4 548 6/18/2024 List of Figures Figure 12-3: Import Encryption Certificate option. . . . . . . . . . . . . . . . . . . . 434 Figure 12-4: Import Project Database Encryption Certificate dialog. . . . . . 434 Figure 12-5: Opening Encryption Certificate File . . . . . . . . . . . . . . . . . . . . 435 Figure 12-6: Import Project Database Encryption Certificate - Password. . 435 Figure 12-7: Informational dialog. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 435 Figure 12-8: EMS Application Server Manager. . . . . . . . . . . . . . . . . . . . . . 436 Figure 12-9: Exporting the Sensitive data encryption certificate. . . . . . . . . 437 Figure 12-10: Export project database encryption certificate dialog . . . . . . 437 Figure 12-11: Exporting the Database file encryption certificate. . . . . . . . . 438 Figure D-1: Project Settings - Project Parameters window . . . . . . . . . . . . . 463 Figure D-2: Smart Card Pin dialog. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 464 Figure D-3: Waiting for USB to be inserted dialog . . . . . . . . . . . . . . . . . . . 464 Figure D-4: Information dialog. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 465 Figure D-5: Program Smart Card screen . . . . . . . . . . . . . . . . . . . . . . . . . . . 466 Figure D-6: Activation Code screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 467 Figure D-7: Editing Activation Codes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 468 Figure D-8: Exporting the Activation Code Configuration File. . . . . . . . . . 468 Figure D-9: Saving the Activation Code Configuration File . . . . . . . . . . . . 469 Figure D-10: Insert poll worker Smart Card. . . . . . . . . . . . . . . . . . . . . . . . . 470 Figure D-11: Enter Poll Worker Pin. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 470 Figure D-12: Browse to Activation Code Configuration File . . . . . . . . . . . 471 Figure D-13: Insert Voter Smart Card . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 472 Figure D-14: Contents of the inserted Smart Card. . . . . . . . . . . . . . . . . . . . 473 Figure D-15: Remove Ejected Card . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 474 Figure D-16: Selecting a Voter Session Activation Code . . . . . . . . . . . . . . 474 Figure D-17: Indicating if Voter Session is Accessible . . . . . . . . . . . . . . . . 475 Figure D-18: Indicating if Voter Session is Challenged. . . . . . . . . . . . . . . . 476 Figure D-19: Programming Voter Card . . . . . . . . . . . . . . . . . . . . . . . . . . . . 477 Figure D-20: Card Successfully Written . . . . . . . . . . . . . . . . . . . . . . . . . . . 477 Figure D-21: Remove Written Card. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 478 Figure F-1: The Ballot Path (Scanning) . . . . . . . . . . . . . . . . . . . . . . . . . . . . 483 Figure F-2: Thermal Printer X-section View . . . . . . . . . . . . . . . . . . . . . . . . 484 Version: 5.19::4 549 6/18/2024 List of Figures Figure F-3: Example Error . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 486 Figure F-4: Batch selection list. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 497 Figure H-1: Re-zero Results. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 506 Figure H-2: Confirmation Dialog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .507 Figure H-3: Figure. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .508 Figure H-4: Figure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 511 Figure H-5: Figure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 512 Figure H-6: Figure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 513 ® Figure H-7: The ImageCast Evolution is physically secured by five color-coded security seals. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 513 Figure H-8: Figure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 515 Figure H-9: Figure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 516 Figure H-10: Sealing the memory card access doors . . . . . . . . . . . . . . . . . . 517 Figure H-11: Sealing the thermal report printer door. . . . . . . . . . . . . . . . . . 518 Figure H-12: Sealing the modem port . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 519 Figure H-13: Figure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 522 Figure H-14: Figure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 522 Figure H-15: Figure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 523 Figure H-16: Top security latch plastic sea . . . . . . . . . . . . . . . . . . . . . . . . . 524 Figure H-17: Bottom security latch plastic seal . . . . . . . . . . . . . . . . . . . . . . 525 Figure H-18: Evidence of tampering adhesive seal . . . . . . . . . . . . . . . . . . . 525 Version: 5.19::4 550 6/18/2024 ® Democracy Suite Use Procedures LIST OF TABLES Table 1-1: ICE’s Major System Elements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 Table 1-2: ICC's Major System Elements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4 Table 1-3: ICP2’s Major System Elements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 Table 1-4: ICX's Major System Elements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 Table 2-1: Paper Stock Approved for ImageCast Ballots. . . . . . . . . . . . . . . . . . . . .24 Table 3-1: EMS Standard Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36 Table 3-2: EMS Workstation Checklist. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49 Table 3-3: BIOS Settings Options - Dell Precision 3450/3460 . . . . . . . . . . . . . . 50 Table 3-4: Application Workstation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 57 Table 3-5: ICVA Workstation Checklist . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .69 Table 3-6: ICC Client Workstation checklist . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 77 Table 3-7: BIOS Settings Options - Dell Precision 3440. . . . . . . . . . . . . . . . . . . . . 77 Table 3-8: BIOS Settings Options - Dell Precision 3450/3460 . . . . . . . . . . . . . . . 79 Table 3-9: BIOS Settings Options - Dell Optiplex 7440/3050/5270. . . . . . . . . . 80 Table 3-10: Scanner Hardware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .98 Table 4-1: List of Functional Tests. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 124 Table 4-2: System Power . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177 Table 4-3: Battery status. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177 ® Table 6-1: ImageCast Evolution Equipment . . . . . . . . . . . . . . . . . . . . . . . . . . . . 184 ® Table 6-2: ImageCast Precinct 2 Equipment. . . . . . . . . . . . . . . . . . . . . . . . . . . . 187 ® Table 6-3: ImageCast X Equipment. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 189 Table 9-1: Standard Voting Outstack Conditions . . . . . . . . . . . . . . . . . . . . . . . . . 371 Table 9-2: Rank Choice Voting Outstack Conditions . . . . . . . . . . . . . . . . . . . . . . 371 Table 9-3: Adjudication - Ballot Navigation Icons . . . . . . . . . . . . . . . . . . . . . . . 395 Table 9-4: Ballot Adjudication Overlays. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 405 Table D-1: Watermark Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 458 Table E-1: Scanner Handling. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .480 Table H-1: Physical Security — Types of Seals. . . . . . . . . . . . . . . . . . . . . . . . . . . .509 Table H-2: Physical Security — Ballot Box Security Seals . . . . . . . . . . . . . . . . . .509 Table H-3: Physical Security — Ballot Box Security Locks. . . . . . . . . . . . . . . . . . 510 6/18/2024 551 Version: 5.19::4 List of Tables Table H-4: Physical Security — Ballot Box Lid Latches . . . . . . . . . . . . . . . . . . . . 512 ® Table H-5: Physical Security — ImageCast Evolution Security Seals. . . . . . . . 514 ® Table H-6: Physical Security — ImageCast Evolution Security Seals. . . . . . . . 515 Table J-1: Democracy Suite EMS Certified Versions. . . . . . . . . . . . . . . . . . . . . . 530 Table J-2: ImageCast Tabulator & BMD Certified Firmware Versions. . . . . . . . 531 Version: 5.19::4 552 6/18/2024 Index INDEX A Accessible Voting ICE ......................................................................................................................243 ICX ......................................................................................................................260 Activation Codes Exporting from EED ...........................................................................................466 Importing to ICVA ..............................................................................................470 Air-gap Configuration Air-gap Isolation ...................................................................................................29 EMS/EED Network Configuration .......................................................................29 Network Configuration .........................................................................................28 C CF/SD Programming the Cards ......................................................................................462 Closing the Polls ICE ......................................................................................................................269 ICP2 ....................................................................................................................275 ICX ......................................................................................................................284 E Election Project Backing Up .........................................................................................................430 Opening ...............................................................................................................147 Restoring .............................................................................................................144 I iButton Programming the Security Key ...........................................................................462 ICE Accessible Voting ...............................................................................................243 Changing the Printer Tape ..................................................................................228 Closing the Polls .................................................................................................269 Early Voting ........................................................................................................179 Polling Place Equipment .....................................................................................184 Provisional Voting ..............................................................................................266 Setting up the Equipment ....................................................................................191 Voting Session Procedures .................................................................................220 ICP2 Closing the Polls .................................................................................................275 Early Voting ........................................................................................................181 Opening the Polls ................................................................................................213 Polling Place Equipment .....................................................................................187 Setting up the Equipment ....................................................................................193 Voting Session Procedures .................................................................................230 ICX Accessible Voting ...............................................................................................260 6/18/2024 553 Version: 5.19::4 Index Closing the Polls .................................................................................................284 Opening the Polls ................................................................................................201 Polling Place Equipment .....................................................................................189 Provisional Voting ..............................................................................................268 Setting up the Equipment ....................................................................................200 Voting Session Procedures .................................................................................240 O Opening the Polls ICP2 ....................................................................................................................213 ICX ......................................................................................................................201 P Poll Worker Card Programming the Card ........................................................................................465 Programming Cards CF/SD .................................................................................................................462 Poll Worker .................................................................................................145, 465 Tech Advisor .......................................................................................................463 Voter Activation Smart Card ..............................................................................471 Provisional Voting ICE ......................................................................................................................266 ICX ......................................................................................................................268 T Tech Advisor PIN Parameters ...................................................................................................463 Programming the Cards ......................................................................................463 U USB Cleaning ..............................................................................................................149 Configuration for Election File Programming Group .........................................463 Election File Programming Group Configuration ..............................................464 V Voter Activation Card Programming the Card ........................................................................................471 6/18/2024 554 Version: 5.19::4 ® Democracy Suite Use Procedures EEnndd ooff DDooccuummeenntt 6/18/2024 555 Version: 5.19::4