All bodies  ›  Office of Voting Systems Technology Assessment  ›  County of Los Angeles Vsap Tally 1.0 Staff Report

OVSTA

County of Los Angeles Vsap Tally 1.0 Staff Report

VSAP Tally Version 1.0

Office of Voting Systems Technology Assessment · vendors-LAC-la-vsap1-staff · Staff report · Los Angeles County VSAP

Read the report at Los Angeles County VSAP ↗

A P LEX ADILLA | SECRETARY OF STATE | STATE OF CALIFORNIA OFFICE OF VOTING SYSTEMS TECHNOLOGY ASSESSMENT 1500 11th Street | Sacramento, CA 95814 | Tel 916.695.1680 | Fax 916.653.4620 | www.sos.ca.gov County of Los Angeles Voting Solutions for All People (VSAP) Tally 1.0 Staff Report Prepared by: Secretary of State’s Office of Voting Systems Technology Assessment July 13, 2018 Table of Contents I. Introduction ......................................................................................... 1 1. Scope ................................................................................... 1 2. Summary of the Application ................................................. 1 3. Contracting and Outsourcing ............................................... 1 II. Summary of the System .................................................................... 2 1. VSAP Tally System, v. 1.1.2.2 ............................................. 2 2. IBML ImageTrac Scanner, v. 6400 ....................................... 2 III. Testing Information and Results ........................................................ 2 1. Background .......................................................................... 2 2. Functional Testing Summary ............................................... 3 3. Software (Source Code) Testing Summary .......................... 5 4. Security and Telecommunications Testing Summary .......... 5 5. Volume Testing Summary .................................................... 18 IV. Compliance with State and Federal Laws and Regulations ............... 20 V. Conclusion .......................................................................................... 26 SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 2 | Page A P LEX ADILLA | SECRETARY OF STATE | STATE OF CALIFORNIA OFFICE OF VOTING SYSTEMS TECHNOLOGY ASSESSMENT 1500 11th Street | Sacramento, CA 95814 | Tel 916.695.1680 | Fax 916.653.4620 | www.sos.ca.gov I. INTRODUCTION 1. Scope This report presents the test results for all phases of the certification test of the County of Los Angeles’ VSAP Tally 1.0. The purpose of the testing is to test the compliance of the voting system with California and Federal laws, including the California Voting System Standards (CVSS). Testing also uncovers other findings, which do not constitute non-compliance, and those findings are reported to the voting system vendor to address the issues procedurally. The procedures for mitigating any additional findings are made to the documentation, specifically the County of Los Angeles Use Procedures. 2. Summary of the Application The County of Los Angeles submitted an application for the VSAP Tally 1.0 central tabulation system on September 19, 2017. The system is comprised of the following major components: Voting Solutions for All People (VSAP) Tally software, version 1.1.2.2; IBML ImageTrac Scanner, version 6400 In addition to these two components, which includes the executable code and the source code, the County of Los Angeles was required to submit the following: 1) the technical documentation package (TDP); 2) all the hardware components to including all peripheral devices needed for the Functional Test Phase the Security and Telecommunications Test Phase; 3) and the VSAP Tally Blended Use Procedures. 3. Contracting and Consulting Upon receipt of a complete application, the Secretary of State released a Request for Quote (RFQ) for assistance with the Software Testing (Source Code Review) and Security and Telecommunications testing. Through the formal California contracting process, the Secretary of State awarded a contract to SLI Compliance (SLI), a division of Gaming Laboratories International, LLC. II. SUMMARY OF THE SYSTEM The VSAP Tally 1.0 solution is solely used for scanning and tabulating ballots. The intent of use for this iteration is to process vote by mail (VBM) ballots. The system will be used in a blended environment, with the County of Los Angeles’ legacy system Microcomputer Tally System (MTS) version 1.3.1 using InkaVote ballots, which will tabulate precinct ballots. The system consists of two components: 1. Voting Solutions for All People (VSAP) Tally software, version 1.1.2.2 The VSAP Tally is a central tabulation software solution. The VSAP Tally system as described in the Los Angeles County 2018 Blended Use Procedures is a transition to scanning technology of digital image that then processes the ballot into Cast Vote Records (CVR). 2. IBML ImageTrac Scanner, version 6400 The IBML ImageTrac is a commercial off-the-shelf (COTS) document scanner. The scanner provides the following functionality for the system: Scans 10,000 ballots per hour Out stacks documents that do not have or are unable to read QR codes and 1d Barcodes. Pre-Print ballot id, name the digital image with the ballot id and scan in the same process. III. TESTING INFORMATION AND RESULTS 1. Background Functional and Volume testing of this system was conducted by Secretary of State Staff, in Norwalk, California, from May 23 to May 25, 2018. The configuration of the equipment, including a build from the ground up, was witnessed by Secretary of State Staff on May 23, 2018, using the configuration procedures provided by the County of Los Angeles. Software testing (Source Code Review) was performed by SLI Compliance June 11 to July 12, 2018. Security and Telecommunications testing was performed in Norwalk, California from July 2 to July 3, 2018. Accessibility for this iteration of the VSAP Tally system will be addressed by the County of Los Angeles internal procedures for employee accessibility. This version is solely for the tabulation of vote-by-mail ballots and exclusively for the use of Los Angeles County election employees. SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 2 | Page 2. Functional Testing Summary System Configuration: Preparation for Functional Testing and all subsequent testing began on May 23, 2018. The system is self-contained on an air gapped network, per the CVSS requirements. Secretary of State staff witnessed the build of the test environment utilizing the vendor provided Use Procedures, which included installation of the operating system, commercial-off-the-shelf (COTS) software, tabulation software, and hardening of the system. SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 3 | Page Issues & Observations During the configuration build, each time the system is built it requires installing the latest updates for the operating system. a. Documentation The documentation was subsequently modified and the changes verified by the Secretary of State staff. Phase I - Functional Testing The first phase of Functional Testing consisted of following the Use Procedures to configure test elections. The testing included defining three (3) different test election definitions. The election type definitions, jurisdictions, and any anomalies noted are listed in the table below: Table 2A: Election Definitions Election Type Jurisdiction Anomaly Identified Resolution General Los Angeles None N/A County Primary – Los Angeles Reports – Sensitivity settings Countywide County Treasurer Contest were adjusted in Vote Center count came out 2/4, the configuration Model instead of 4/4. file. The ballot was rerun five (5) times, Ballot Out Stack – and each time it Superintendent of came out clear after Education and making the Measure I. One adjustment. ballot had debris that could not be seen with naked eye, but the scanner picked it up a valid count. Recall Election Los Angeles None N/A - Fictional County Contest with 72 Candidates and Yes/No Recall Question SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 4 | Page 3. Software Testing (Source Code) Review Summary The review was conducted at the SLI Compliance offices located in Wheat Ridge, Colorado. SLI evaluated the security and integrity of the voting system, by identifying any security vulnerabilities that could be exploited to: Alter vote recording, Alter vote results, Alter critical data (such as audit logs), or Conduct a “denial of service” attack on the voting system. There were no discrepancy findings or vulnerabilities identified within the VSAP Tally 1.1.2.2 code base. 4. Security and Telecommunications Testing Security and Telecommunications testing of the VSAP Tally system was conducted from July 2 to July 3, 2018, by SLI Compliance. The security and telecommunications testing was conducted in four phases as follows: Phase I – Security Documentation Review Phase II – Functional Security Testing Phase III – Telecommunications and Data Transmission Testing Phase IV – Onsite Security Testing Phase I – Security Documentation Review SLI Compliance reviewed the security documentation supplied by Los Angeles County, and determined there were no vulnerabilities with the documentation. SLI did note that there were some improvements, five (5) minor findings with vague or partially missing documentation. Table 4A: Security Documentation Review Test Results Vendor Mitigation/Response CVSS 7.4.6 – The Following locations must exist and be writable by the system: Documentation is only present to validate /opt/mounts (mounted into docker) VSAP Tally Containers and Trusted Build /opt/tally (scripts, configuration) outputs, and base package installation of /mount/ballots COTS software. Detailed documentation for validation of all storage locations The following must exist but should not be associated with election specific writeable: information was missing. /var/lib/docker SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 5 | Page Table 4A: Security Documentation Review Test Results Vendor Mitigation/Response /mount/ballots should also have sufficient room for all the ballot images that will be generated in the election with sufficient safety margin. CVSS 7.4.5 – VSAP Tally System Version 1.1.2.2 is designed for internal use by Los Angeles Documentation was present for creation of County only. It will only be installed in the a build environment for the VSAP Tally County’s secure central count facility and solution as well as building the will not be distributed to any other environment; however, the documentation locations. has limited references as to how software is distributed and where the certified copy Prior to installation in the central count of the software will be stored. There is facility, a copy of the software will be mention in the documentation that the obtained from a software escrow company solution will only be used by LA County. certified with the California Secretary of State and the security hashes for the download will be validated. CVSS 7.4.4.b – A more complete list of files will be compiled and provided. There is reference to parts of the system being considered static, dynamic or a mix of both, the list of files was not complete or extensive. CVSS 7.4.2 – County will perform malware/anti-virus and vulnerability scanning after system Documentation was present indicating that installation in the air-gapped due to performance requirements the environment. In addition, an offline scan solution will not actively utilize COTS anti- will be performed prior to each batch virus software during operation of the processing of production ballots for every solution. There are, however, election. supplemental mitigation steps including anti-virus and vulnerability scanning of the environment systems prior to being introduced to an air gapped network. CVSS 7.4.1 – In the VSAP Tally System Air-Gap Setup document provided, Los Angeles County Documentation was provided that has documented the procedure to setup an describes the basic overall features air-gap network and configure all requirements and processes for creation connected devices in the County central and management of an air gapped facility. network. In some cases it is detailed, such has how to update software or firmware on SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 6 | Page Table 4A: Security Documentation Review Test Results Vendor Mitigation/Response the air gapped systems and software without internet connectivity. No full procedure for a start to finish air gapped network implementation including hardware connectivity is available. Phase II – Functional Security Testing Functional Security Testing includes testing the relevant software and operating system configuration for vulnerabilities, and testing of the hardware, including examination of unused hardware ports and security measures applied to those ports. Functional Security Testing also included verifying the VSAP Tally system meets the applicable requirements of the CVSS. Table 4B: Functional Security Testing Findings lists the applicable sections of the CVSS, in addition to the findings of the testing conducted by SLI. A response to those findings is also included by the County of Los Angeles. Table 4B: Functional Security Testing Findings Test Results Vendor Mitigation/Response CVSS 7.4.2 – County will perform malware/anti-virus and vulnerability scanning after system The actual outcome for this review was a installation in the air gapped environment. determination that during operations, the In addition, an offline scan will be performed systems within the Scanner environment prior to each batch processing of production as well as the systems within the VSAP ballots for every election. Tally environment do not actively use COTS anti-virus protection. The system instead utilizes initial malware/anti-virus and vulnerability scanning prior to the systems being introduced to the air gapped network. These are mitigation steps that are being relied upon instead of active malicious software protection. CVSS 7.4.6 – VSAP Tally System Version 1.1.2.2 is designed to be installed and operated in an The actual outcome for this review environment with tight physical controls. was a determination that there are There is no external network connection to validation methods to verify the allow processes to access external VSAP Tally 1.0 trusted build software. output as well as a JSON file created with a list of every VSAP Tally System Version 1.1.2.2 is not SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 7 | Page Table 4B: Functional Security Testing Findings Test Results Vendor Mitigation/Response container generated by the build designed for distribution and will only be process and a corresponding hash used by Los Angeles County in a tightly- value. Each of the COTS products controlled environment. Physical, contain a hash of the single COTS administrative, and management controls file installation file(s). This that include strict supervision and indicates that the software monitoring of staff activity while operating validation is done prior to the the Tally System and the prohibition of installation of the system. wireless phones\devices and unverified removable media in the secure Tally room The actual outcome for this review are some of the mitigation measures that was a determination that there are will be implemented to ensure integrity of processes and procedures for the air gapped network. creation of SHA512 Hash codes during the trusted build for both the system build outputs and SHA256 hashes of each of the Docker service containers. All COTS Software contains verifiable HASH values to validate that the correct version of the software is installed. The system has no protections to prevent processes from installing software except for manual processes and procedures and physical security and access controls to prevent unauthorized installation. The VSAP Tally 1.0 system utilizes processes and procedures and physical security and access controls to prevent previous versions of the system from being installed. The software update package is not digitally signed. The Solution doesn’t currently utilize an automated process to prevent unwanted installations The system doesn’t have a way to provide a verification method of all system storage locations, only the VSAP Tally 1.0 solution, and the COTS products installers. SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 8 | Page Table 4B: Functional Security Testing Findings Test Results Vendor Mitigation/Response CVSS 7.6.1 – Ballot security and accountability is critically important for the County. Each ballot has a QR Code with election-specific information The actual outcome for this review encoded, which VSAP Tally reads to ensure was a determination that portions the ballot is valid in the current election. of this requirement are not applicable. The system scans Additionally, controls are implemented as already marked ballots which are part of the Use Procedures to inspect all then processed by the VSAP Tally ballots prior to tabulation and to ensure only system. valid official ballots are sent to VSAP Tally No checksums or message for processing. digests are used to validate scanned ballot images. Manual recount procedures, California State required one percent manual recount procedures, physical security measures and a tightly controlled air gapped network are all mitigating measures in place. CVSS 7.8.2 - Physical, administrative, and management controls that include strict supervision and The actual outcome for this review monitoring of staff activity while operating was a determination that the the Tally System and the prohibition of solution sufficiently protects wireless phones\devices and unverified against data interception and removable media in the secure Tally room disruption. are some of the mitigation measures that will be implemented to ensure integrity of The solution currently does not the air gapped network. A major feature of provide end to end transmission this network is that the network switch being security. The VSAP Tally 1.0 used is configured to only allow one device solution utilizes encryption of data per port and locks that port to the device’s transmissions between Application mac address. containers for image processing and reporting. The connection between the IBML Scanner and the CIFS file share, however, is not transmitted using encryption. Stringent attention to maintaining the air gapped scanner and Tally environment removes the ability to intercept or modify results as they are being scanned and processed. SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 9 | Page Phase III – Telecommunications and Data Transmission Testing Telecommunications and Data Testing included testing of system communications, including encryption of data, as well as protocols and procedures for access authorization. Table 4C list the results of that testing. Table 4C: Telecommunications and Data Transmission Vulnerabilities Issue Consultant Assessment Vendor Mitigation/Response Cross Site (High Severity) (Tentative Cross Site Scripting requires Scripting confidence) Potentially a false having another (malicious) site (DOM-based) positive as the confidence is set accessible on the network. This is to tentative. prevented by strict enforcement of the air gapped network environment and security protocols. SSL Certificate (Medium severity) (Certain As noted, this issue is mitigated confidence). Server’s certificate is by the strict enforcement of the air not valid for the server’s gapped network environment and hostname, and the server security protocols. certificate is not trusted. This error has little to no impact to the overall security of the solution due to the nature of the air gapped trusted network. Client-side (Low Severity) (Firm Confidence). Strict enforcement of the air JSON injection DOM-based JSON injection may gapped network environment and (DOM-based) happen when a script includes security protocols should provide controllable data into a string that sufficient protection against DOM- is parsed as a JSON data based attacks. structure and then processed by the application. Transport (Low Severity) (Certain Strict enforcement of the air security confidence). This allows a gapped network environment and potential attacker to modify security protocols should provide legitimate user network traffic to sufficient protection against these bypass application use of types of attacks. SSL/TLS encryption. Informational These vulnerabilities are of an Although as noted these Vulnerabilities informational nature and include vulnerabilities are believed to be recon information that helps to negligible, they are mitigated by identify the system, including open the strict enforcement of the air ports, OS type and version and gapped network environment and services detected. The security protocols. vulnerabilities explored and SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 10 | Page detected are believed to be negligible and have little or no impact on the overall security of the system. SLI reported three (3) categorical findings during the Telecommunications and Data Transmission Testing of the VSAP Tally 1.0 system. SLI’s determination was that, the overall security posture of the system as a whole is minimal. The findings are listed below in Table 4D. Table 4D: Telecommunications and Data Transmission Categorical Issue Consultant Assessment Vendor Mitigation/Response Six (6) medium 1. SMB signing not required VSAP Tally operates in an air severity gapped network. Strict access 2. SSL Certificate cannot be vulnerabilities trusted controls and physical security mitigation measures are 3. SSL Certificate signed using implemented to ensure the weak hashing algorithm integrity of the air gapped 4. SSL certificate with wrong host environment. name 5. SSL medium strength cipher suites supported 6. SSL Self-signed Certificate Two (2) low 1. SSH Server CBC mode ciphers VSAP Tally operates in an air severity enabled gapped network. Strict access vulnerabilities 2. SSL RC4 cipher suites controls and physical security supported. mitigation measures are implemented to ensure the integrity of the air gapped environment. Fifty (50) These vulnerabilities are of an Although as noted these informational informational nature and include vulnerabilities are believed to be severity recon information that helps to negligible, they are mitigated by vulnerabilities. identify the system, including open the strict enforcement of the air ports, OS type and version and gapped network environment and services detected. The security protocols. vulnerabilities explored and detected are believed to be negligible and have little or no impact on the overall security of the system. SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 11 | Page Phase IV – Onsite Security Testing The Onsite Security Testing consisted of testing for relevant software and operating system configuration for vulnerabilities, testing of hardware, including the examination of unused ports and the security measures applied to the ports, in addition to examination of the physical environment. The applicable portions of CVSS and the results of the Onsite Security Testing are listed in Table 4E. Table 4E: Onsite Security Testing CVSS Standard Result Vendor Mitigation/Response CVSS 5.4.3 - The actual outcome for N/A this review was a a. Machine generated error and determination that the exception messages to system generates and demonstrate successful contains sufficient recovery. auditing capability. This includes VSAP Tally 1.0 iv. Notification of system logs, Centos Operating login or access errors, System logs, Windows file access errors, and OS logs, ImageTrac logs. physical violations of security as they occur, and a summary record of these events after processing CVSS 7.2.1 – The actual outcome for N/A this review was a a. Voting system equipment determination that the shall provide access control system sufficiently mechanisms designed to permit provides access controls authorized access to the voting for the VSAP Tally 1.0 system and to prevent solution, as well as the unauthorized access to the systems that are voting system. associated with the solution. The system has i. Access control processes and mechanisms on the procedures in place to Election Management prevent System (EMS) shall be modification/tampering capable of identifying with software/firmware, as and authenticating well as physical security individuals permitted to including an air gapped perform operations on network. the EMS. b. Voting system equipment shall provide controls that SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 12 | Page Table 4E: Onsite Security Testing CVSS Standard Result Vendor Mitigation/Response permit or deny access to the device’s software and files. c. The default access control permissions shall implement the minimum permissions needed for each role or group identified by a device. d. The voting device shall prevent a lower-privileged process from modifying a higher-privileged process. e. An administrator of voting system equipment shall authorize privileged operations. f. Voting system equipment shall prevent modification to or tampering with software or firmware through any means other than the documented procedure for software upgrades. CVSS 7.2.2 – The actual outcome for N/A this review was a a. The voting system shall determination that the identify users and processes to access controls are which access is granted and sufficient for all portions of the specific functions and data the VSAP Tally 1.0 to which each entity holds environment, including authorized access. Scanner environment. b. Voting system equipment that implements role-based access control shall support the recommendations for Core RBAC in the ANSI INCITS 359- 2004 American National Standard for Information Technology- Role Based Access Control document. c. Voting system equipment SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 13 | Page Table 4E: Onsite Security Testing CVSS Standard Result Vendor Mitigation/Response shall allow the administrator group or role to configure the permissions and functionality for each identity, group, or role to include account and group/role creation, modification, and deletion. CVSS 7.3 – The actual outcome for N/A this review was a a. Voting system equipment determination that all shall authenticate users prior to username password granting them access to system functionality is maintained functions or data. by an administrative source. Complex b. When private or secret passwords, lockout authentication data is stored in history, complexity voting system equipment, the requirements, and data shall be protected to expiration of passwords ensure that the confidentiality can all be enforced at the and integrity of the data is not operating system level violated. and at the ImageTrac scanning software which c. Voting system equipment sufficiently meets the shall allow the administrator requirements. group or role to set and change passwords, pass phrases, and keys. d. Voting system equipment shall allow privileged groups or roles to be disabled and allow new individual privileged groups or roles to be created. e. Voting system equipment shall lock out groups, roles, or individuals after a specified number of consecutive failed authentication attempts within a predefined time period. f. Voting systems shall allow the administrator group or role to configure the account lock out policy, including the time SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 14 | Page Table 4E: Onsite Security Testing CVSS Standard Result Vendor Mitigation/Response period within which failed attempts must occur, the number of consecutive failed access attempts allowed before lock out, and the length of time the account is locked out. g. If the voting system uses a user name and password authentication method, the voting system shall allow the administrator to enforce password strength, histories, and expiration. h. The voting system shall allow the administrator group or role to specify password strength for all accounts, including minimum password length, use of capitalized letters, use of numeric characters, and use of non- alphanumeric characters. i. The voting system shall enforce password histories, and allow the administrator to configure the history length. j. Voting system equipment shall ensure that the username is not used in the password. k. Voting systems shall provide a means to automatically expire passwords in accordance with the voting jurisdiction’s policies. l. Manufacturers shall develop and document in detail the measures to be taken in a central counting environment. These measures shall include physical and procedural SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 15 | Page Table 4E: Onsite Security Testing CVSS Standard Result Vendor Mitigation/Response controls related to the handling of ballot boxes, preparing of ballots for counting, counting operations and reporting data. CVSS 7.3.2 – The actual outcome for In the VSAP Tally this review was a System Air-Gap Setup Manufacturers shall develop determination that the document provided, Los and document in detail the solution fully documents Angeles County has measures to be taken in a and implements documented the central counting environment. processes and procedure to setup an These measures shall include procedures for securing air-gap network and physical and procedural the central count location. configure all connected controls related to the handling These include physical devices in the County of ballot boxes, preparing of security measures, central facility. ballots for counting, counting procedural controls for operations and reporting data. maintaining the Air Gap In the VSAP Tally network, protection and System Tamper-Evident handling of ballots, and Seals Procedures reporting of data. document provided, Los Angeles County has Observation: No specific documented how it details pertaining to the intends to log the use security measures to tamper-evident seals as network switching a security measure. equipment. Security practices for the air gapped network were observed that help to enhance the overall security of the solution but were not documented anywhere in the requirements. Observation: There is reference to maintaining tamper-evident seal numbers multiple times throughout the documentation; however, there is no direct reference to the tamper evident seal log that was in use. Documentation of the procedures for SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 16 | Page Table 4E: Onsite Security Testing CVSS Standard Result Vendor Mitigation/Response maintaining such a log including where it’s stored and who has access to the log is needed. CVSS 6.1.2 – The actual outcome for N/A this review was a These requirements apply to determination that the the use of telecommunications system sufficiently meets to transmit data for the the requirements for data preparation of the system for an transmission. Testing election, the execution of an included Nessus® election, and the preservation Vulnerability scans of the system data and audit against all connected trails during and following an equipment, as well as election. While this section physical inspection of the does not assume a specific networking equipment model of voting system connected to the air operations and does not gapped network. assume a specific model for the use of telecommunications to support such operations, it does address the following types of data, where applicable: Voter Authentication: Coded information that confirms the identity of a voter for security purposes for a system that transmits votes individually Ballot Definition: Information that describes to a voting machine the content and appearance of the ballots to be used in an election Vote Count: Information representing the tabulation of votes at any level within the control of the jurisdiction, such as the polling place, precinct or central count List of Voters: A listing of the individual voters who have cast ballots in a specific election CVSS 7.8.1– The actual outcome for N/A this review was a SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 17 | Page Table 4E: Onsite Security Testing CVSS Standard Result Vendor Mitigation/Response For those access control determination that the features built in as components solution successfully of the voting system, the S-ATA meets the requirements shall design tests to confirm for access control. that these security elements work as specified. Specific activities to be conducted by the S-ATA shall include: b. Specific tests designed by the S-ATA to verify the correct operation of all documented access control procedures and capabilities, including tests designed to circumvent controls provided by the manufacturer. These tests shall include: i. Performing the activities that the jurisdiction will perform in specific accordance with the manufacturer’s access control policy and procedures to create a secure system, including procedures for software and firmware installation ii. Performing tests intended to bypass or otherwise defeat the resulting SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 18 | Page Table 4E: Onsite Security Testing CVSS Standard Result Vendor Mitigation/Response security environment. These tests shall include simulation of attempts to physically destroy components of the voting system in order to validate the correct operation of system redundancy and backup capabilities CVSS 7.8.2 – The actual outcome for Physical, administrative, this review was a and management For systems that use determination that the controls that include strict telecommunications, as solution sufficiently supervision and provided for in section 6 of the protects against data monitoring of staff activity Standards and consistent with interception and while operating the Tally California law, to transmit disruption. The utilization System and the official voting data, the SATA of a physically protected prohibition of wireless shall review, and conduct tests air gapped network helps phones\devices and of, the data interception and improve a solution that unverified removable prevention safeguards specified only employs encryption media in the secure Tally by the manufacturer in its TDP. of data transmissions room are some of the The S-ATA shall evaluate between application mitigation measures that safeguards provided by the containers for image will be implemented to manufacturer to ensure their processing and reporting ensure integrity of the air proper operation, including the and not all gapped network. A proper response to the communications. The major feature of this detection of efforts to monitor connection between the network is that the data or otherwise compromise IBML Scanner and the network switch being the system. CIFS file share is not used is configured to only currently encrypted. allow one device per port Stringent attention to and locks that port to the maintaining the air device’s mac address. gapped scanner and Tally environment removes the ability to intercept or modify results as they are being scanned and processed. SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 19 | Page SLI determined there were three (3) findings and two (2) observations during the Onsite Security Testing Phase. SLI concluded the impact to the overall security posture of the solution as a whole is minimal. 5. Volume Testing Summary The Volume Test simulates conditions in which the system components would be used on Election Day. Volume Testing of the VSAP Tally system took place in Los Angeles County, on May 24, 2018. Test ballots from the California 2014 General Election were scanned for over seven (7) hours. The use of this election required an edit of the configuration file within the Tally system. Table 5A: Machine and Ballot Count Hardware Number of Number of Ballot Pages Total for All Component Machines Ballots per Machines Machine IBML Scanner 1 2,998 Two (2) 5,996 Table 5B: Error Log Hardware Component Error Type Error Occurrence Mitigation Frequency IBML Scanner “Gap Violation” – The Ten (10) The use scanner is sensitive procedures and to the amount of operator cards spacing between at the scanner ballots in the feeder. will remind operators of the scanner that adequate spacing between the ballots in the feeder is necessary. IBML Scanner “Double Feed Error” One (1) IBML – Two ballots were suggested stuck together. adjustments to the scanner to alleviate gap and double SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 20 | Page Table 5B: Error Log Hardware Component Error Type Error Occurrence Mitigation Frequency feed errors. Those suggestions were incorporated into the daily maintenance routine; operators will follow during the tally process. Additionally, operators should utilize a “ballot jogger”. Use procedures will address this issue. IBML Scanner “Document too long One (1) Ballot was error” pulled off of track and delicately hand fed into the scanner. IBML Scanner Ballot Out stacked One (1) Slight fold in the corner of ballot, covering the registration mark. Use procedures will address this issue. SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 21 | Page IV. COMPLIANCE WITH STATE AND FEDERAL LAWS AND REGULATIONS The following are the applicable California Elections Code sections that the Secretary of State tested the County of Los Angeles’ VSAP Tally 1.0 central tabulation voting system against. The list is broken down by Elections Code Section, language quoted from the section and how the system complies with the section. 10264 - As soon as the result of the election is declared, the elections official of the governing body shall enter on its records a statement of the result. The statement shall show: (a) The whole number of votes cast in the city. (b) The names of the persons voted for. (c) The measures voted upon. (d) For what office each person was voted for. (e) The number of votes given at each precinct to each person and for and against each measure. (f) The number of votes given in the city to each person and for and against each measure. The central tabulation voting system has the capability to produce the required report(s). 10550 - As soon as the result of the canvass by the county elections official is declared, the county elections official shall prepare and mail a statement of the result to the secretary of each district participating in the general district election. The statement shall be signed by the county elections official, authenticated by the seal of the county and shall show: (a) The number of ballots cast for elective offices of that district and, when directors of that district are elected by divisions, the number of ballots cast in each division. (b) The name of each candidate for an elective office of that district voted for and the office. (c) The number of votes cast in each precinct for each candidate. (d) When directors are elected by divisions, the number of votes cast in each division for each candidate for the office of director from that division. (e) The number of votes cast in the district for all other elective offices of that district. The central tabulation voting system has the capability to produce the required report(s). 15101(b) - Any jurisdiction having the necessary computer capability may start to process vote by mail ballots on the seventh business day prior to the election. Processing vote by mail ballots includes opening vote by mail ballot return envelopes, removing ballots, duplicating any damaged ballots, and preparing the ballots to be machine read, or machine reading them, but under no circumstances may a vote count be accessed or released until 8 p.m. on the day of the election. All other jurisdictions shall start to process vote by mail ballots at 5 p.m. on the day before the election. The central tabulation voting system has the capability to meet this requirement. SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 22 | Page 15101(c) - Results of any vote by mail ballot tabulation or count shall not be released prior to the close of the polls on the day of the election. The central tabulation voting system has the capability to scan, but not tabulate or report the results prior to the close of polls on Election Day. 15109 - Except as otherwise provided in this chapter, the counting and canvassing of vote by mail ballots shall be conducted in the same manner and under the same regulations as used for ballots cast in a precinct polling place. The central tabulation voting system has the capability to meet this requirement. 15110 - Reports to the Secretary of State of the findings of the canvass of vote by mail ballots shall be made by the elections official pursuant to Chapter 3 (commencing with Section 15150) and Chapter 4 (commencing with Section 15300). The central tabulation voting system has the capability to produce the required report(s). 15150 - For every election, the elections official shall conduct a semifinal official canvass by tabulating vote by mail and precinct ballots and compiling the results. The semifinal official canvass shall commence immediately upon the close of the polls and shall continue without adjournment until all precincts are accounted for. The central tabulation voting system has the capability to meet this requirement. 15151(a) - The elections official shall transmit the semifinal official results to the Secretary of State in the manner and according to the schedule prescribed by the Secretary of State prior to each election, for the following: (1) All candidates voted for statewide office. (2) All candidates voted for the following offices: (A) State Assembly. (B) State Senate. (C) Member of the United States House of Representatives. (D) Member of the State Board of Equalization. (E) Justice of the Court of Appeals. (3) All persons voted for at the presidential primary or for electors of President and Vice President of the United States. (4) Statewide ballot measures. The central tabulation voting system has the capability to produce the required report(s). 15152 - Neither the elections official, any member of a precinct board, nor any other person shall count any votes, either for a ballot proposition or candidate, until the close of the polls in that county. After that time, the ballots for all candidates and ballot propositions voted upon solely within the county shall be counted and the results of the balloting made public. However, the results for any candidate or ballot proposition also voted upon in another county or counties shall not be made public until after all the polls in that county and the other county or counties have closed. This paragraph applies regardless of whether the counting is done by manual tabulation or by a vote tabulating device. The central tabulation voting system has the capability to scan, but not tabulate or report the results prior to the close of polls on Election Day. SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 23 | Page 15153 - During the semifinal official canvass, write-in votes shall be counted in accordance with Article 3 (commencing with Section 15340) of Chapter 4. The central tabulation voting system has the capability to meet this requirement. 5212 - If voting at all precincts within a county is not conducted using the same voting system, the result as to the precincts not subject to this article shall be determined in accordance with other provisions of this code and the result of the vote at precincts subject to this article shall be determined as provided in this article. The statement of the vote in that case shall represent the consolidation of all the results and the results of the canvass of all vote by mail voter ballots. The central tabulation voting system has the capability to produce the required report(s). 15302(e), (f), (g), (h) - The official canvass shall include, but not be limited to, the following tasks: (e) Processing and counting any valid vote by mail and provisional ballots not included in the semifinal official canvass. (f) Counting any valid write-in votes. (g) Reproducing any damaged ballots, if necessary. (h) Reporting final results to the governing board and the Secretary of State, as required. The central tabulation voting system has the capability to produce the required report(s). 15342(a) - Any name written upon a ballot for a qualified write-in candidate, including a reasonable facsimile of the spelling of a name, shall be counted for the office, if it is written in the blank space provided and voted as specified below: (a) For voting systems in which write-in spaces appear directly below the list of candidates for that office and provide a voting space, no write-in vote shall be counted unless the voting space next to the write-in space is marked or slotted as directed in the voting instructions, except as provided in subdivision (f). (d) Neither a vote cast for a candidate whose name appears on the ballot nor a vote cast for a write-in candidate shall be counted by a combination of marking and writing, a choice of more names than there are candidates to be nominated or elected to the office. (e) All valid write-in votes shall be tabulated and certified to the elections official on forms provided for this purpose, and the write-in votes shall be added to the results of the count of the ballots at the counting place and be included in the official returns for the precinct. The central tabulation voting system has the capability to meet this requirement. 15372(a) - The elections official shall prepare a certified statement of the results of the election and submit it to the governing body within 28 days of the election or, in the case of school district, community college district, county board of education, or special district elections conducted on the first Tuesday after the first Monday in November of odd numbered years, no later than the last Monday before the last Friday of that month. (b) The elections official shall post the certified statement of the results of the election on his or her Internet Web site in a downloadable spreadsheet format that may include, but is not limited to, a comma-separated values file or a tab-separated values file and that is compatible with a spreadsheet software application that is widely used at the time SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 24 | Page of the posting. The certified statement of the election results shall be posted and maintained on the elections official’s Internet Web site for a period of at least 10 years following the election. This subdivision shall apply only to an elections official who uses a computer system that has the capability of producing the election results in a downloadable spreadsheet format without requiring modification of the computer system. The central tabulation voting system has the capability to produce the required report(s). 15374(a) - The statement of the result shall show all of the following: (1) The total number of ballots cast. (2) The number of votes cast at each precinct for each candidate and for and against each measure. (3) The total number of votes cast for each candidate and for and against each measure. (b) The statement of the result shall also show the number of votes cast in each city, Assembly district, congressional district, senatorial district, State Board of Equalization district, and supervisorial district located in whole or in part in the county, for each candidate for the offices of presidential elector and all statewide offices, depending on the offices to be filled, and on each statewide ballot proposition. The central tabulation voting system has the capability to produce the required report(s). 19101(b)(1) - The machine or device and its software shall be suitable for the purpose for which it is intended. The central tabulation voting system meets this requirement. 19101(b)(2) - The system shall preserve the secrecy of the ballot. The central tabulation voting system meets this requirement. 19101(b) (3) – The system shall be safe from fraud or manipulation. The central tabulation voting system meets this requirement. 19203 - The Secretary of State shall not certify or conditionally approve a voting system or a part of a voting system that uses paper ballots unless the paper used for the ballots is of sufficient quality that it maintains its integrity and readability throughout the retention period specified in Chapter 4 (commencing with Section 17300) of Division 17. The ballots used for testing the central tabulation voting system have the capability to meet this requirement. 19204 - The Secretary of State shall not certify or conditionally approve any voting system that includes features that permit a voter to produce, and leave the polling place with, a copy or facsimile of the ballot cast by the voter at that polling place. The central tabulation voting system has the capability to meet this requirement. SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 25 | Page 19205 - A voting system shall comply with all of the following: (a) No part of the voting system shall be connected to the Internet at any time. (b) No part of the voting system shall electronically receive or transmit election data through an exterior communication network, including the public telephone system, if the communication originates from or terminates at a polling place, satellite location, or counting center. (c) No part of the voting system shall receive or transmit wireless communications or wireless data transfers. The central tabulation voting system has the capability to meet this requirement. V. CONCLUSION The VSAP Tally 1.0 voting system, in the configuration tested and documented by the California Installation and the County of Los Angeles’ Use Procedures, meets all applicable California and federal laws. The County of Los Angeles’ VSAP Tally 1.0 voting system is compliant with all applicable California and federal laws. SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 26 | Page