All bodies  ›  Office of Voting Systems Technology Assessment  ›  Use Procedures

OVSTA

Use Procedures

VSAP Tally Version 1.0

Office of Voting Systems Technology Assessment · vendors-LAC-lac-vsap-use-proc · Use procedures · Los Angeles County VSAP

Read the report at Los Angeles County VSAP ↗

Los Angeles County 2018 Blended Use Procedures COUNTY OF LOS ANGELES REGISTRAR-RECORDER/COUNTY CLERK (RR/CC) VOTING SOLUTIONS FOR ALL PEOPLE (VSAP) TALLY SYSTEM V. 1.0 May 7, 2018 --------------------------------------------------------------------------------- Table of Contents 1. INTRODUCTION 6 1.1. System description and components 6 1.2. Terms and Definitions 6 2. BALLOT DEFINITION 9 2.1. Overview 9 2.2. Paper and printing specifications 10 2.2.1. Ballot printing specifications 10 2.2.2. Ballot paper specifications 10 2.2.3. Ballot stub 11 2.3. Layout requirements and specifications 11 3. SYSTEM INSTALLATION AND CONFIGURATION 15 3.1. Tally System and Aggregator Application hardware requirements and specifications 15 3.2. Hardware and network set-up and configuration 17 3.3. Software installation and configuration 17 3.4. Acceptance Testing Certification Procedures 18 3.5. Software and firmware upgrades 18 4. ELECTION SET-UP AND DEFINITION 18 4.1. Programming and configuration of election management system/software, including audit records to be generated and retained 18 4.2. Programming and configuration of vote recording/tabulation devices, including audit records to be generated and retained 19 4.2.1. Tally System 19 4.2.2. Aggregator Application 21 4.3. System diagnostic testing procedures, including audit records to be generated and retained 22 4.4. System proofing 22 4.5. Logic and accuracy testing of system and components 23 4.5.1. Pre-conditions for performance of tests, including test decks 23 4.5.2. Accuracy Test procedures 23 4.5.3. Logic Test procedures 24 4.5.3.1. Process Ballots 28 4.5.4. Retention of test materials 30 VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 2 4.5.5. Logic and Accuracy Board and certification of testing 30 4.6. Ballot tally programs 30 4.7. Election Observer Panel 31 4.8. Hardware maintenance and preparation for use 31 5. POLLING PLACE PROCEDURES 31 5.1. Precinct Ballot Reader (PBR) procedures 32 5.2. Polling place set-up 32 5.3. Polling place procedures 32 5.4. Special needs voters 33 5.5. Closing the polls 33 5.6. Troubleshooting and problem resolution 34 6. ABSENTEE/MAIL BALLOT PROCEDURE (CENTRAL TABULATION) 34 6.1. System start-up and pre-tabulation report procedures 34 6.1.1. Start Tally Services 34 6.1.2. Tally Manager 35 6.2. Tabulation procedures 36 6.3. Post-tabulation report and shutdown procedures 36 6.3.1. Shutdown procedures 37 7. SEMI-OFFICIAL AND POST-ELECTION PROCEDURES 37 7.1. System start-up and pre-tabulation reports 37 7.1.1. Start Tally Services 38 7.1.2. VSAP Tally Manager 39 7.2. Processing VBM Ballots 39 7.3. Processing vote reports 39 7.3.1. Central tabulation 40 7.3.2. Precinct tabulation 40 7.4. Integration with other systems and Calvoter 40 7.4.1. Aggregator Application 40 7.4.2. Calvoter 41 8. OFFICIAL CANVASS AND POST-ELECTION PROCEDURES 42 8.1. Canvassing Ballots Voted on the Audio Ballot Booth 42 8.2. Canvassing VSAP VBM Ballots 42 8.2.1. In-house VBM Remake Application 42 8.2.2. Tally System Reprocess Ballots 43 8.2.3. In-house Ballot Storage Application 43 VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 3 8.2.3.1. Ballot Storage Scan Point 1 43 8.2.3.2. Ballot Storage Scan Point 2 44 8.2.3.3. Finding a ballot 44 8.3. Canvassing precinct returns 44 8.4. Canvassing provisional ballots 44 8.5. Canvassing write-in votes 44 8.6. 1% Manual Recount Procedures 48 8.7. Handling ballot exceptions 49 8.8. Post-election logic and accuracy testing 51 8.9. Final reporting of official canvass 51 8.10. Backup and retention of election material 51 8.10.1. Archive Election 51 8.10.2. Run reports 52 8.10.3. Export 52 9. MANUAL RECOUNT PROCEDURES 53 10. SECURITY 53 10.1. Physical security of system and components 53 10.2. Logical security of system and components 54 10.2.1. Essential and non-essential services and ports 54 10.2.2. User-level security 55 10.2.3. Anti-virus protection 56 10.2.4. Procedures verifying, checking, and installing essential updates and changes 56 10.2.4.1. Audit records for the changes showing what, when, who, and why 56 10.2.4.2. Installation procedures for those updates which would normally be installed using an internet connection 57 10.2.4.3. Acceptance testing after the installation. 57 10.3. Security procedures for central processing 57 10.3.1. Facility access procedures 58 10.3.2. VBM ballot procedures 58 10.3.3. Election night procedures 59 10.4. Security procedures for polling places 59 10.5. Audit trails 59 11. Biennial Hardware Certification and Notification 59 11.1. Notification 60 11.2. Certification of logic and accuracy testing 60 11.3. Logic and Accuracy Board 60 VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 4 11.4. Election Night and Post-Election Reporting 61 VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 5 1. INTRODUCTION 1.1. System description and components ● Los Angeles County InkaVote Optical Scan Voting System ● Microcomputer Tally System (MTS) Version 1.3.1 ● ES&S InkaVote Plus Precinct Ballot Counter (PBR) Voting System 1.10 ● Unisyn Gateway Components Version 1.1 ● Los Angeles County VSAP Tally System Version 1.1.2.2 Overview A critical piece of Los Angeles County’s Voting Solutions for All People (VSAP) is the VSAP Tally System solution, which scans ballots and tabulates the votes. The Tally System is both unique and innovative, and like other components of VSAP, is challenging the election industry to look at the design and engineering of voting solutions in a new and modern way. There is enormous potential to make a positive impact on voting systems development and implementation both in California and throughout the United States. The VSAP Tally System Version 1, as prescribed by the Use Procedures document, is intended to process full-face Vote-by-Mail (VBM) ballots. Los Angeles County’s previous VBM ballot used a 312 vote position ballot card based on the IBM Hollerith card with pre-printed ovals for inking votes. The Tally System is a transition to a scanning technology of a digital image that then processes the ballot into Cast Vote Records (CVR). CVRs are ballot summaries of every ballot that the Tally System is able to tabulate and report results. For precinct voting, Los Angeles County uses the certified Microcomputer Tally System (MTS) Version 1.3.1 using InkaVote ballots. Information on vote at poll ballots are in the InkaVote Use Procedures. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 6 1.2. Terms and Definitions Terms Brief Description Absentee An absentee ballot is also known as a Vote by Mail (VBM) Ballot ballot. Voters mark the VBM Ballot and then mail it or drop off the ballot at an authorized location during an election. There are roughly 2.2 million permanent Vote by Mail voters. Accuracy Test VBM ballot card test deck are processed through Tally System’s document scanners. Vote marks are printed to meet minimum thresholds. Tests verifies scanners and the Tally System interpret the VBM ballot correctly. Adjudication Refers to the handling of write-in votes, provisional ballots, damaged, or other ballots that have been outstacked by the system as “unable to process”. Automated Process of generating ballot vote pages in an Election Ballot Layout Management System. (ABL) Ballot Image Scanned image of a ballot in a digital format. Ballot Style Ballot styles, which include contests, candidates, language and how these contests are laid out on marksense ballots by style, and any other data required to compute the election results. Ballot Card Identifier of the physical ballot card in a multi-paged ballot Ballot Group It is a combination of candidate offices and ballot measures to be voted on at elections. There maybe one combination because of activating districts that are not in elections. Damaged A ballot card which has been torn, bent or mistreated so that Ballot it cannot be processed through the card reader or document scanner. Lead Sheet A sheet of paper processed through the Tally System with a printed ballot box identifier used for ballot storage. Ballots processed after the start lead sheet and before the end lead VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 7 sheet are recorded to be in that box. Logic and Test used to verify the equipment's ability to read all vote Accuracy (L&A) positions and also insure that vote tally programs and hardware correctly interpret, summarize and report votes for a specific elections. Logic Test Processing of election specific ballot decks with predetermine results to insure the tally software and election data correctly tabulate ballots. Microcomputer Certified Los Angeles County central tabulation system. Tally System Currently supports the InkaVote ballot. (MTS) Over Vote The condition that arises when the voter votes for more candidates than the number of candidates to elect. Spoiled Ballot A ballot card which has been torn, bent, or mistreated so that it cannot be processed through the card reader Write-in A write-in candidate is a candidate in an election whose name does not appear on the ballot, but for whom voters may vote nonetheless by writing in the person's name. Zero Report Election results report with 0 ballots cast. Used to check that all the Tally System results is cleared. Acronym Definition Brief Description BAM Ballot Activation Mechanism Method of activating a BMD for voting using BPM QR Code, or Poll Worker Manual BMD Activation BDF Ballot Definition File One of four election data files from EMS: describes contests, contest data, and unique selection IDs BLDF Ballot Layout Definition FIle One of four election data files from EMS: describes physical layout of both BMD selections-only ballot and VBM ballot BPM Ballot Page Metadata QR code describing contents of VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 8 physical page, including ballot layout and status flags for BMD or VBM ballots, or other system pages (lead sheet/self-test/precinct header/report/etc) CVR Cast Vote Record Record containing refined set of voter selections and contest counters after Election rules applied ECBMS Election Contest and Ballot Current RR/CC election contest and Management System ballot layout system EMS Election Management System Describes combination of the Tally-external systems including ECBMS, DIMS-net, GIS Election System, Ballot Accountability EOC Elections Operations Center Los Angeles County facility used for staging, deploying, and recovering election hardware and supplies IBML Imaging Business Machines, Manufacture of ImageTrac Series L.L.C. document scanners L&A Logic and Accuracy L&A testing is a series of tests conducted prior to processing ballots to ensure the Tally system is correctly reading and tabulating votes MTS Microcomputer Tally System Current MS-DOS based Tally system (MTS) for 312-position Inkavote ballots RRCC Los Angeles County Registrar of voters office for Los Registrar-Recorder County Angeles County Clerk SBR Selections Ballot Record Record containing unrefined set of voter selections PBH Press Bulletin Header File containing headings and contest sequence used for the press bulletin TLDF Tally Layout Definition File One of four election data files from EMS: describes layout of physical of ballot as needed by Tally Recognizer for finding registration marks, ballot VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 9 id, QR codes, and Vote Position Targets (CA SoS Term) VSAP Voting Solutions for All People Voting system project designed and implemented by Los Angeles County 2. BALLOT DEFINITION 2.1. Overview InkaVote Ballots The InkaVote optical scan paper-based ballot cards used by voters have been printed in accordance with the governing InkaVote Use Procedures approved by the Secretary of State for use with the InkaVote Optical Scan Voting System. Audio ballot slips created by voters who vote on the Audio Ballot Booth component of the InkaVote Plus system will be printed in accordance with the Use Procedures approved by the Secretary of State for use with the InkaVote Plus PBR Voting System 1.10. All audio ballot slips created using the InkaVote PBR Audio Ballot Booth will be manually reproduced onto InkaVote ballot cards during the canvass period so that they can be tabulated by the InkaVote Optical Scan Voting System prior to compilation of the Official Vote totals. VSAP VBM Ballots Print quality and paper stock must be tested and evaluated by Los Angeles County in order to the certify ballot printer with the California Secretary of State. 2.2. Paper and printing specifications 2.2.1. Ballot printing specifications ● Corner cut or black corner print ● Duplex ● Color ● DPI VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 10 2.2.2. Ballot paper specifications Specification Value Grain Direction on Finished Ballot Long Basis Weight 80# Text weight (36.2874 kg) Thickness 0.0061 in. (0.015494 cm) Smoothness 130 Sheffields Moisture 5.5 percent Opacity 97.0 Brightness 92 to 94 PPI 338 Length (small, medium large) 11”, 14”, 17” Width (small, medium, large) 8.5”, 8.5”, 11” 2.2.3. Ballot stub A one inch stub will be attached on the top of the VBM ballot. This stub is used by the mailing vendor to quality check the VBM ballot and verify it has been correctly mailed to the correct voter in the mail assembly process. The voter is instructed to remove the stub before returning the ballot. 2.3. Layout requirements and specifications Ballot Layout Specifications The VSAP full-face VBM ballot layout was designed based on usability principles in AIGA Design for Democracy's Designing usable ballots Field Guide to make ballots as easy to use and accessible as possible. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 11 VBM ballots can be created in different sizes. A small ballot is 8”x11”, medium size ballot is 8.5”x14” and a large size ballot is 11”x17”. Different ballot sizes are available to accommodate different election size. The size of the the ballot affects the number of contests per page, the number of ballot cards per voter and usability of the ballot. Using the size based on minimizing unused space improves portability and reduces mailing and printing costs. The VBM layout is designed for the Tally System: ● The Recognizer identifies the BPM QR code to determine the ballot style. ● The VBM Recognizer identifies the registration marks to create a Cartesian grid on the ballot. ● Designated area for ballot ID printing VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 12 Figure : Front Page Layout VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 13 Figure : Back Page Layout and Fonts VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 14 Figure : Measure and Registration Layout VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 15 3. SYSTEM INSTALLATION AND CONFIGURATION InkaVote Ballots Los Angeles County will comply with the Use Procedures approved by the Secretary of State for the InkaVote Optical Scan Voting System with respect to acceptance testing, installation and configuration. Los Angeles County will comply with the Use Procedures approved by the Secretary of State for the InkaVote Plus PBR Voting System with respect to acceptance testing, installation and configuration of the PBR devices. 3.1. Tally System and Aggregator Application hardware requirements and specifications The Tally System is a central tabulation software solution. Each piece of hardware utilized by the Tally System is commercially available off-the-shelf (COTS). While it is recommended all pieces of hardware are thoroughly evaluated by the end user, the Tally System only requires sufficiently powerful servers, and IBML ImageTrac series scanners that can scan images in grayscale at 300 DPI. The Tally System is designed around a secure air-gapped network environment located in the Los Angeles County RR/CC Micro Tally System (MTS) Room. Below is detailed list of hardware and software the Tally System consists of. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 16 Figure : The VSAP Tally System Diagram IBML ImageTrac Document Scanners Versatile high speed document scanners are needed for the Tally System to process large amounts of ballots. An IBML ImageTrac is a commercial off-the-shelf document scanner that is setup and maintained by the manufacturer. The scanner meets the following needs of the Tally System: ● Fast throughput at approximately 10,000 ballots per hour per scanner. ● In real time, able to out stack documents that do not have or are unable to read QR codes and 1d Barcodes without stopping. When scanning millions of ballots, the ability to identify unreadable ballots before the Tally System is critical in Canvass operations by eliminating the need to have staff find ballots that need to be rescanned. ● Ability to pre-print a ballot id, name the digital image with the ballot id and scan in the same process. Pre-printing the ballot id enables the scanner to capture the VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 17 printed ballot id on the digital image. The ballot id is vital to searching and matching the digital image with the physical paper ballot. ● Stable and consistent images are needed by the Tally System to process mark sense digital image recognition to interpret the voter’s intent on the ballot. 3.2. Hardware and network set-up and configuration The Tally System is an air gapped network physically isolated from the public Internet and County building network. Servers are connected through a network gigabit switch using 5e rated network cables. Server configuration instructions are available in the Tally System User Guide . The Aggregator Application runs on a standalone COTS PC that is not connected to any network. Digital media is used to input and output data. 3.3. Software installation and configuration Setting up the build and production environment. The following installation and configuration steps are available in the Tally System User Guide. Install Centos 7.4 desktop and follow the recommendations: 1. Install Centos 7.4 2. Setup Docker and Docker-Compose 3. Install Git 4. Build Deployment Package 5. Setup CIFS File Server 6. Configure Tally System Node 7. Deploy Tally System 8. Create System Files 9. Generate SSL Keys and Certificates 10. Create Signing Keys 11. Configure Yaml Scripts 12. Configure Election VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 18 3.4. Acceptance Testing Certification Procedures All specialized vote tabulating software and equipment must be certified for use in elections by the Secretary of State prior to use in any election. Certification procedures are available upon request from the Secretary of State's Elections Division. 3.5. Software and firmware upgrades The Tally System is on an air gapped network that physically prevents any software or firmware updates to be done automatically. Any necessary software or firmware changes will be moved to the server via digital media and installed locally. Any firmware installs for the scanner servers will be provided directly from the IBML the scanner manufacture. 4. ELECTION SET-UP AND DEFINITION 4.1. Programming and configuration of election management system/software, including audit records to be generated and retained Los Angeles County will program the election in MTS, including district, contest and candidate set-up, precinct consolidation and ballot layout. System reports will be proofed for correct election definition and data. All audit records and reports will be retained as legally required. Election Contest and Ballot Management System (ECBMS) is an in-house Registrar-Recorder/County Clerk (RR/CC) developed system that acts as the central platform for managing the filing and qualification of contests, candidates and measures. Centralizing data eliminates redundancy and ensures ballot information is accurately laid out on vote recorders, sample ballot booklets and VBM ballots. ECBMS generates “print ready” photo compositions of Vote Recorder pages and VBM ballots that are reviewed and approved directly on the computer screen by department staff prior to sending the documents (PDF format) to the print vendor for mass production. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 19 4.2. Programming and configuration of vote recording/tabulation devices, including audit records to be generated and retained Election definition and data from Los Angeles County’s MTS will be exported according to the system specification and used to create the vote recorder pages necessary to vote using the voter recorder devices of the InkaVote Optical Scan Voting System, in accordance with Use Procedures approved by the Secretary of State. All audit records will be generated and retained as specified by the Use Procedures for the InkaVote Optical Scan Voting System approved by the Secretary of State. The InkaVote Plus PBR devices will NOT be used to officially record or tabulate votes . The PBR devices will only be used to provide second-chance voting. The ABB units will be available for use by those voters with disabilities as well as LEP or other voters who indicate a preference for voting via the audio process. Election definition and data files from MTS will be transferred to the Election Converter application, which converts it to a PBR-compatible format. The election definition and data in the PBR-compatible format is then loaded into each of the PBR devices using the Election Loader application. Both the Election Converter and the Election Loader applications are modules of the Unisyn Gateway Components 1.1 software, which is certified for use with the InkaVote Plus PBR Voting System 1.10. All audit records will be generated and retained as specified by the Use Procedures for the InkaVote Plus PBR Voting System 1.10 approved by the Secretary of State. 4.2.1. Tally System At the Tally System start-up, a configuration file is used to identify the election and its data file. The configuration file (services-docker-compose.yml located in the /opt/tally/ directory of the machine with services) contains all the data file path locations. When an election is changed, the locations of these must be modified within services-docker-compose.yml. The pertinent election data is defined in the Ballot Definition File (BDF), Tally Layout Definition File and Press Bulletin Header (PBH) files. The date and time of an election, as well as the election title, are defined in the BDF. The BDF and TLDF contains the ballot layout and the PBH holds the headings and contest sequence used for the press bulletin. These files are referenced by the services-docker-compose.yml file. Once the Tally System environment is setup and election files are created the election can be loaded by following the steps below: 1. Create a ballot configuration directory: /opt/mounts/ballot_configs directory. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 20 sudo mkdir -p /opt/mounts/ballot_configs 2. Move the election files (BDF, TLDF, and PBH) into that directory as root. sudo cp 0001_BDF.json 0001_TLDF.json 0001_PBH.json /opt/mounts/ballot_configs 3. Configure the environment variables in the services-docker-compose.yml file. For single node deployment (stand alone Tally server), services-docker-compose.yml can found on the Tally machine. For the two node deployment (multi-server Tally), services-docker-compose.yml can be found on the services machine. tallymanager: ... ## Change these values to change the election (see comment at top of file for full list). The BDF and TLDF must match BDF_FILE_NAME: 0001_BDF.json TLDF_FILE_NAME: 0001_TLDF.json ... tabulate: ... ## Change these values to change the election (see comment at top of file for full list) - This must match the BDF + TLDF HEADER_FILE_NAME: 0001_PBH.json ... Each Tally System service log events are logged on the file system. The logs are preserved for auditing. Users with server administrator permission can access logs on the Services server at /opt/mounts/tally_logs (the location is specified in the services-docker-compose.yml file). Users with server administrator permission can access logs on the Providers server at /opt/mounts/kaa (the location is specified in the providers-docker-compose.yml file). Log file names appear as follows: [service][logfileidnumber].json. The system generates one log file per service instance and writes all logs for that service instance into that single file. Each entry is written with a severity (info, warn, error, fatal), VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 21 along with a type (see previous section), a message and an action. Below are the available services with log files: ● Auth ● Ballot Viewer ● Cluster Manager ● Receive ● Recognize ● Refine ● Tabulate ● Tally Manager Each log entry is a JSON formatted string on a single line to allow for easy parsing. The file itself is not a JSON file, to make appending more efficient. Although user logs are not split out from system logs, almost all user related log entries will be in the Tally Manager and Auth service logs. Logs created by receive, recognize, refine, outstack, will ether be ballot level logs or system logs. Any ballot level issue will also be reported via an outstack record which will be visible in the ballot viewer. 4.2.2. Aggregator Application The Tally System scans and tallies VSAP VBM ballots and sends the results file to the Aggregator Application. The Aggregator Application merges both the new Tally System and MTS results files to generate a press bulletin and publish results. Aggregator Application setup requires a set of data files needed to start the services necessary for the aggregation process. Below is a description of the setup process: ● Create a folder structure for the application. ○ Root folder named Aggregator ○ Input folder in the Aggregator folder ○ Output folder in the Aggregator folder ○ Log folder in the Aggregator folder ○ Archive folder in the Aggregator folder ● Copy Aggregate program in the Aggregator folder ● Copy the following election data files into the Input folder: ○ Ballot Definition File (BDF) ○ Counter Mapping File - MTS and new Tally System Counter ID Mapping ○ Press Bulletin Header File - contest and registration data are being loaded. Aggregator Application stores an event log in the Aggregator/log folder. The log file is generated and updated in real time. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 22 4.3. System diagnostic testing procedures, including audit records to be generated and retained Los Angeles County will comply with the Use Procedures for the InkaVote Optical Scan Voting System approved by the Secretary of State. Los Angeles County will comply with the Use Procedures for the InkaVote Plus PBR Voting System 1.10 approved by the Secretary of State. The successful Logic and Accuracy tests, conducted at the time of certification (or recertification, if necessary) to the Secretary of State, storage logs or records, if any, and balancing reports, if any, shall be retained as long as the ballots are kept for the election. The official logic test ballot cards used for balancing prior to and upon completion of processing official ballots shall also be kept for as long as the ballots are kept. Back-up decks and other test decks may be destroyed or used to train operators for other elections. 4.4. System proofing For system proofing of the InkaVote Optical Scan Voting System, Los Angeles County will comply with the Use Procedures approved by the Secretary of State. For system proofing of the InkaVote Plus PBR Voting System 1.10, Los Angeles County will comply with the Use Procedures approved by the Secretary of State. This includes all audio ballot scripts that support the Audio Ballot Booths. Los Angeles County will proof ballot information for all VBM ballot groups: ● Correct assignment of contests to ballot types ● Correct assignment of candidates to contests ● Correct assignment of “Vote For” number to contests ● Candidate names ● Occupational designations ● District and contest names Tally System proofing is the mandatory preliminary, in-house testing of the computer hardware and software used to tally and summarize votes. System proofing shall include, but is not limited to, verification of the correctness of the following: VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 23 ● Election night summary results report format produced by the Aggregator Application ● Preparation of box identification cards (start and end box cards) ● Registration totals 4.5. Logic and accuracy testing of system and components Logic and accuracy testing will be completed on the InkaVote Optical Scan Voting System as required in the Use Procedures approved by the Secretary of State. Logic and accuracy testing will be completed on all InkaVote Plus PBR units as required in the Use Procedures approved by the Secretary of State for InkaVote Plus PBR Voting System 1.10. Logic and accuracy testing is a series of tests conducted prior to processing ballots to ensure the Tally System is correctly scanning, interpreting and tabulating votes. 4.5.1. Pre-conditions for performance of tests, including test decks During the production of Official VBM ballots, the certified ballot printer delivers production election ballots watermarked with “TEST”. These ballots are processed through the Tally System to verify the Official ballots process properly and meet the ballot paper specifications. 4.5.2. Accuracy Test procedures Accuracy Testing consists of processes and procedures necessary to ensure hardware to be used in the election is working properly, both as individual units and as a combined system. Emphasis is placed on verifying that ballot scanners are setup and tuned to produce a ballot image the Tally System expects. These tests shall be run before Logic testing in order to assist in isolating problems. Accuracy tests are an integral part of equipment maintenance and may be run as often as necessary before each election to ensure proper functioning of hardware as well as ballot cards used in the tallying process. The Accuracy Test Deck consists of: ● 250 ballot cards (page 1 and page 2) ● 250 ballot cards (page 3 and page 4) ● Total of 7 contests 150 voted candidates VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 24 ● BPM QR Code Accuracy Testing Procedures: 1. Turn scanner on 2. Open the IBML Test Job Profile 3. Load the test cards 4. Start the scanning ballots 5. Start the Tally System in test mode (see Section 4.5.3) 6. Proof Press Bulletin that all candidates received 250 votes 4.5.3. Logic Test procedures Logic testing consists of those processes and procedures necessary to ensure vote tally programs and hardware correctly interpret, summarize and report votes for a specific election. This is normally conducted with a series of tests using ballot cards or ballot images. The test is performed using real election data files and a set of ballot images with predetermined results. Successful testing demonstrates: ● Each candidate / ballot measure receives predetermined number of votes; ● Each precinct is assigned the correct ballot style; ● The system reports the proper number of over and under votes; ● The system accepts only the proper ballot types and rejects improper ones; ● The system accepts only the multilingual ballots set for the election. The Vote by Mail Logic tests shall be run prior to pre-processing ballots for each election. The results of each run shall be balanced to the predetermined results. The predetermined results for balancing of election processing must be available for inspection and signed off by the Logic and Accuracy Board described in Section 11.4. A Certificate of Official Logic Testing must be completed, certified, and received by the Secretary of State seven days before each statewide election. Once the L&A is complete the system election totals are cleared and verified through a zero results bulletin. At this time the system is secured and ready for ballots to be scanned. All Tally program(s) and hardware must remain operative from the time of the pre-ballot processing logic test, through the processing of all voted ballots. Any failure, such as a power failure, which affects the central processing unit (CPU) and requires the program to be reloaded, shall require a new set of Logic and Accuracy testing before any ballots can be processed. The logic test ballot cards or digital ballot images shall be tabulated in the Tally test mode. The resulting logic vote tallies VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 25 shall be compared in detail with the predetermined logic vote tallies. Any differences between the two logic vote tallies shall be resolved, and logic testing shall be performed as many times as necessary to achieve a logic vote tally which is identical to the predetermined count. After balancing the two logic vote tallies, the logic test ballots and the documentation shall be locked in a facility with restricted access or sealed. Logs or records shall be maintained, recording each use of the logic test and by whom it was completed. The logic test data shall contain: ● “Voted” Test Ballots A group of test ballots (images) shall be voted in such a way that each Candidate for every Office on the ballot receives a predetermined number of votes that are different from the number of votes received by any other Candidate for the same Office. One vote in the first position, two votes in the 2nd position, etc. Also, the number of “Yes” votes on any ballot Measure shall receive a different number of predetermined votes than the number of “No” votes. ● “Over Voted” Test Ballots One test ballot (image) shall be an “over voted” test ballot, on which every contest office and ballot measure has more votes than is allowed. A vote will not be marked in an “over voted” test ballot for an uncontested office. ● “No Votes” or Under Voted Test Ballots One “no votes” test ballot (image) shall not contain any marks other than those needed for precinct or ballot type identification. This test should result in under votes being cast for each contest on that ballot (image). Tally Manager has now been configured to know where to find the election definition files. Put Tally Manager into Test Mode . Only Admin users can run the Tally Manager website in either test mode or election mode, start services, export, import and generate tabulation reports. To start Tally Manager, follow the steps for finding and running the correct scripts described in the Tally System Setup d ocument. The steps for a two-node deployment are below: 1. From the console on the providers machine, go to the /opt/tally directory. 2. Run the script. sudo python scripts/run.py -t providers # providers machine deployment 1. From the console on the services machine, go to the /opt/tally directory. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 26 2. Run the following script. sudo python scripts/run.py -t services # services machine deployment Once Tally Manager has started (typically a few minutes), in a Chrome browser, log in as an admin user. Only the Chrome browser is supported. Figure: Logging in Navigate to Manage > Test Mode Controls in the page header. Click the Activate Test Mode button. Figure: Activating test mode The Activate Test Mode prompt is displayed. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 27 Figure: Confirmation prompt to activate test mode In the activate test mode pop-up, click the O K button. Figure: Active test mode display Notice on the home page, any instance of Services (Receive, Recognize, Refine and Tabulate) display the status text of Gone . This is because putting Tally Manager into test mode will kill those processes. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 28 4.5.3.1. Process Ballots From the console on the file server machine of a two-node development, place ballots in the /srv/ballots directory. Once the ballots have copied into the folder, create new instances of the services in the following order: ● Recognize - Navigate to Services Status > Recognizers and choose the number of instances needed from the drop down, then click the Add Instances button. (The number of services needed depends upon the number of ballots to recognize, platform computing power, RAM, etc.) Figure: Status of Recognize service ● Refiner - Navigate to Services Status > Refiners and choose the number of instances needed from the drop down, then click the Add Instances button. (The number of refiner services needed is typically 1 but may need to be adjusted higher for efficiency.) VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 29 Figure: Status of Refine service ● Tabulate - Navigate to Services Status > Tabulator and click the Add Instance button. ● Receive - Receive service starts the entire process of receiving, recognizing and refining the ballots. Navigate to Services Status > Receivers and choose the number of instances needed from the drop down, then click the Add Instances button. (One receive service can be started for each scanner directory.) Figure: Status of Receive service The user can navigate to the Home page and view the Tally Manager Status while the ballots are being counted. Updates in this window will display automatically. Successes for each service signify that each operation successfully completed. Receive is processing image pairs, Recognize and Refine are each processing VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 30 messages. For Tabulate, successes signify the number of successful tabulations run by the election official (each new Tabulation ID described in the section below signifies a success). These numbers are provided to help the operator understand the state and health of the system. For precise numbers use the Ballot Summary Report. 4.5.4. Retention of test materials The successful logic and accuracy tests, conducted at the time of certification (or recertification, if necessary) to the Secretary of State, storage logs or records, if any, and balancing reports, if any, shall be retained as long as the ballots are kept for the election. The official logic test ballot cards used for balancing prior to and upon completion of processing official ballots shall also be kept for as long as the ballots are kept. Back-up decks and other test decks may be destroyed or used to train operators for other elections. 4.5.5. Logic and Accuracy Board and certification of testing Logic test requirements apply to all elections; however, submission of the seven-day certification of logic testing to the Secretary of State is required only prior to statewide elections and elections to fill vacancies in the legislature or congress. 4.6. Ballot tally programs Los Angeles County will comply with the Use Procedures for the InkaVote Optical Scan Voting System with MTS approved by the Secretary of State. Since the PBR devices deployed for the Election will not be used to tally official votes, there is no requirement to submit the ballot tally program for the InkaVote Plus PBR Voting System to the Secretary of State at this time. Tally System programs for statewide and special elections are to be deposited with the Secretary of State no later than seven days prior to each statewide election. The elections official’s certification of testing as well as the list of vote counting equipment used must accompany ballot tally programs. Refer to Elections Code section 17500. Should changes be required following certification and submission to the Secretary of State, resubmission and re-certification is required. 4.7. Election Observer Panel All procedures prescribed in this document shall be carried out in full view of the public insofar as feasible. In addition, the responsible elections official shall devise a plan, whereby all critical procedures of the vote tallying process described in this document are open to VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 31 observation by an Election Observer Panel. Representatives of the qualified political parties and representatives of the news media shall be among those invited to serve on this Panel and shall be given the opportunity to observe that the correct procedures have been followed in the receiving, processing and tallying of all the voted ballots. 4.8. Hardware maintenance and preparation for use Los Angeles County will comply with the Use Procedures for both the InkaVote Optical Scan Voting System, and the InkaVote Plus PBR Voting System approved by the Secretary of State. Los Angeles County is responsible for maintaining Tally System hardware and software (in a secure tally facility) in satisfactory operating condition. Maintenance includes testing and software updates (if needed). Parts replacement are performed specifically to prevent failures from occurring. IBML ImageTrac Scanner on site preventive maintenance is performed once a month by the manufacturer. 5. POLLING PLACE PROCEDURES General Procedures Except as noted in section 5.2, Los Angeles County will comply with the Use Procedures for the InkaVote Optical Scan Voting System as approved by the Secretary of State, with respect to: ● Precinct supplies, delivery and inspection ● Polling place set-up ● Opening the polls ● Polling place procedures ● Provisional voters ● Closing the polls and vote reporting ● Securing audit logs and backup records ● Troubleshooting and problem resolution 5.1. Precinct Ballot Reader (PBR) procedures Supplies, Delivery and Inspection. Each Precinct Inspector will pick up the PBR, ABB and other election supplies from a designated distribution center prior to Election Day and will transport equipment to the polling place on Election Day. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 32 The PBR supplies will include: ● The PBR device with Audio Ballot Booth ● A PBR-compatible ballot box ● One or more spare rolls of audio ballot slips ● One or more spare rolls of PBR thermal printer paper ● A power strip with surge protection ● An 20-ft electrical extension cord Upon arrival at the voting site, the Inspector will unload the supplies and bring the equipment into the polling place, where the equipment will be fully inspected. Any lifting of the PBR device during unloading is specified to be done by two people (each PBR.contains a large, color team lift sticker on the top). The Inspector will request assistance from another poll worker. 5.2. Polling place set-up Los Angeles County will follow Equipment Setup procedures pertaining to the PBR devices and ABB units as specified in the Use Procedures for the InkaVote Plus PBR Voting System 1.10 approved by the Secretary of State. 5.3. Polling place procedures After completion of voting on the InkaVote vote recorder device, the voter will approach the PBR device situated on top of the ballot box. At this point, the voter (or the poll worker if the voter hands him/her the ballot) will remove the top stub from the ballot card and insert it into the ballot reader slot of the PBR device. The PBR reads the ballot card and one of the following situations results: ● If the PBR reads the ballot and detects no ballot alerts, the PBR accepts the ballot and deposits it into the ballot box below the PBR device. The PBR Clerk sees that a Cast Successful message appears on the PBR screen and the Public Count is incremented. The voter keeps the ballot stub as proof of voting. ● If the PBR cannot read the ballot, the ballot ejects and displays an error message, such as Invalid Ballot or Invalid Ballot Style on the PBR screen. The ballot card may have the wrong Precinct ID or may be damaged. The Precinct Clerk or Inspector retains and stores any spoiled ballot card with a note describing the circumstance. If the ballot is spoiled, the voter is given a replacement ballot. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 33 ● Each ballot inserted into the ballot reader slot will be scanned for over-votes on individual contests, or for a completely under-voted ballot (i.e., no votes were recorded/blank ballot). When the PBR encounters an over-voted contest, or a completely under-voted ballot, the PBR prints a ballot alert report and displays Ballot Alert on the PBR screen. When a Ballot Alert occurs: ● The PBR ejects the ballot card back to the voter. ● The PBR prints a Ballot Alert report on the report printer. This report lists the contests and the kind of error that occurred. The PBR Clerk can use a Print button to reprint the report in one of the other programmed languages, if the voter so requests. ● The PBR Ballot Clerk gives the voter the report from the printer to show him/her what problem occurred. ● The PBR Clerk asks the voter if he/she would like to submit the voted ballot “as is,” or vote a replacement ballot. If the voter responds requesting the ballot to be cast “as is”, the PBR Clerk presses the Override button and the voter re-inserts the “as is” ballot containing the noted error(s). Or, at the voter’s request, the PBR Clerk can “spoil” the ballot and issue a replacement ballot to the voter. 5.4. Special needs voters Los Angeles County will follow Special Needs Voters procedures in accordance with the Use Procedures and within all applicable legal parameters. 5.5. Closing the polls Once the Inspector announces the polls are closed, and all voters who were in line by 8 p.m. have had the opportunity to vote, the PBR Clerk selects Close on the system. No more votes may be cast using the PBR device. The PBR Clerk then performs the following: ● Shuts down the PBR device in accordance with Closing procedures and then unplugs the PBR. ● With the help of the Inspector or another poll worker, the device is lifted off the PBR device off of the ballot box. ● Helps the Inspector remove all ballots from the ballot box. Ballots read by the PBR device are collected from the main ballot box compartment. Absentee ballots are placed in designated envelopes, provisional ballots are placed in designated envelopes and ballots from voters who chose not to use the PBR device, are VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 34 collected from the secondary ballot box compartment. Voted ballots not in envelopes are packed and sealed in the Red Box. ● Packs the PBR device and ABB equipment following the instructions in the equipment setup sheets. Packs other supplies. ● With the help of the Inspector or poll worker, loads the PBR device, ABB, and other election supplies for transport. ● Transports the PBR device, ABB and other election supplies from the polling place site to the designated collection center. 5.6. Troubleshooting and problem resolution All Inspectors will be specially trained in all aspects of the setup, opening, operation, closing, packing and transport of the PBR device and ABB. Each Inspector will be issued a cell phone and the cell phone number of a designated coordinator who has been trained in troubleshooting and problem resolution of the PBR/ABB device and who can dispatch a replacement PBR or ABB from a nearby regional distribution center if necessary. A dedicated Help Desk will be set up at the Norwalk headquarters for an additional communication opportunity for Inspectors. In the event a PBR or ABB malfunctions, it will be shut down and all subsequent voters will deposit their ballots directly into the ballot box until a replacement PBR or ABB is deployed by a precinct coordinator or troubleshooter. 6. ABSENTEE/MAIL BALLOT PROCEDURE (CENTRAL TABULATION) 6.1. System start-up and pre-tabulation report procedures Once the Tally System Environment is setup and the election is configured, you can start the system for tabulation. 6.1.1. Start Tally Services The following individual commands can be run to start the services. The -t/--type argument accepts two valid options, Services and Providers . If the type parameter is not passed, the run script will assume it is being executed on the single Tally machine deployment. The scripts are run from the /opt/tally directory. sudo python scripts/run.py # single node Tally machine deployment VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 35 sudo python scripts/run.py -t services # services machine deployment sudo python scripts/run.py -t providers # providers machine deployment If this is the first time starting the environment, or if the database has been cleared, provide the -seed argument (or --seed-db argument) to empty and recreate the base schema for tally in the database. This will erase all existing database data. For single node deployment, the script should be run on the Tally System machine. For the two node deployment, the script should be run on providers machine. Single node Tally machine sudo python scripts/run.py -seed Two node providers machine sudo python scripts/run.py -seed -t providers If the -d/--detached argument is passed, the Tally System will start detached from terminal, running as a background process. sudo python scripts/run.py -d 6.1.2. Tally Manager The Tally Manager is the Tally System user interface. It is designed to work on the Google Chrome browser. Other browsers are not supported. 1. Open Chrome Browser. 2. Enter the ip address 192.168.7.80 3. Log in VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 36 Figure: VSAP Tally Manager Login Screen 6.2. Tabulation procedures Tabulation can begin once the Tally System is configured, services have started and the Tally Manager has been logged on. For processing ballots see section 4.5.3.1. 6.3. Post-tabulation report and shutdown procedures Figure: Report Screen Reporting Options ● Press Bulletin - Summary of results by contest ● Election Results Files - JSON file containing results by precinct with every contest and candidate counter and its value VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 37 ● Audit Logs - See Section 4.2 ● Box File - JSON file linking all Ballot IDs to a Box ID and precinct (reporting unit) 6.3.1. Shutdown procedures In order to stop the tally environment when running detached, execute the stop script. sudo python scripts/stop.py If you wish to clean up the docker containers being used you can execute the cleanup script. If you do not pass any parameters this does not affect the state or data in the system. If you are running on a Provider or Services machine, rather than a single node deployment, you must pass the type property. sudo python scripts/cleanup.py In order to clear out provider data when switching election, three folders need to be removed on either the single node instances or the providers node. sudo rm -rf /opt/mounts/kaa sudo rm -rf /opt/mounts/zookeeper sudo rm -rf /opt/mounts/cassandra/tally 7. SEMI-OFFICIAL AND POST-ELECTION PROCEDURES Los Angeles County will comply with the Use Procedures approved by the Secretary of State for the InkaVote Optical Scan Voting System. (Ballots cast using the Audio Ballot Booth by special needs voters will be re-made onto InkaVote ballot cards after election night as noted in 8.1 below). 7.1. System start-up and pre-tabulation reports Once the Tally System Environment is setup and and the election is configured you can start the system for tabulation. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 38 7.1.1. Start Tally Services The first step is to start the Tally System services. To start the services you provide a start script. There are several command line options that will need to be provided for different setups. The following are the individual commands that can be run to start the services. The -t/--type argument accepts two valid options, “services” and “providers”. If the type parameter is not passed, the run script will assume it is being executed on the single Tally machine deployment. The scripts are run from the /opt/tally directory. sudo python scripts/run.py # single node Tally machine deployment sudo python scripts/run.py -t services # services machine deployment sudo python scripts/run.py -t providers # providers machine deployment If this is the first time starting the environment, or if the database has been cleared, provide the -seed argument (or --seed-db argument) to empty and recreate the base schema for tally in the database. This will erase all existing database data. For single node deployment, the script should be run on the Tally System machine. For the two node deployment, the script should be run on providers machine. Single node Tally System machine sudo python scripts/run.py -seed Two node providers machine sudo python scripts/run.py -seed -t providers If the -d/--detached argument is passed, the Tally System will start detached from terminal, running as a background process. sudo python scripts/run.py -d VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 39 7.1.2. VSAP Tally Manager The Tally Manager is the Tally System user interface. It is designed to work on the Google Chrome browser. Other browsers are not supported. 1. Open Chrome Browser 2. Enter address 192.168.7.80 3. Log in For processing ballots see section 4.5.3.1. 7.2. Processing VBM Ballots All staff processing VBM ballots are required to check in with a Tally System supervisor and sign a log in sheet with date, time and scan station. When work is completed or assignments change, staff are to sign out with date, time and scan station. VBM ballot processing roles per scanner: ● One staff operating the scanner. Role includes loading, removing and starting the scanner. ● One supervisor is responsible for managing and monitoring a scanner. ● Input runners are used for moving boxes of unprocessed ballots to scanners and assist preparing ballots for scanner operator including unboxing and jogging ballots. ● Output runners used to box processed ballots and move them to staging area for ballot storage. ● One snag Operator for every two scanners. Manages ballots not able to be processed by the scanner and reports them to ballot remakes. ● Ballot storage operators scan processed ballot boxes with a storage location. Instructions on operating the ballot scanners are available in the System Operation Manual. 7.3. Processing vote reports Once all the ballots have gone through Receive, Recognize, and Refine and have returned to IDLE status, the user can view reports. From the Home page header, click on a menu tab labeled Tabulate/Reports. This displays a page with two subsections: Generate New Reports and Past Tabulation Reports. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 40 Figure: Generate Report Screen Click the Generate Reports button, and after a short time a new Tabulation ID link will be generated. Click on the Tabulation ID link and review the Semi-Final Election results that display in a new browser tab. Navigate back to the Tabulate/Reports tab and click on the Generate Final Reports button. After a short time, a new Tabulation ID link will be generated. Click on the Tabulation ID link and review the Final Election results that display in a new browser tab. Once both the Semi-Final Election Results and Final Election Results pages have been reviewed, you may close the browser tabs. Navigating back to the Reports browser tab, you may reload the page and see that new entries under Past Tabulation Reports now display. These were the reports that you previously generated. 7.3.1. Central tabulation Tabulation can begin once the Tally System is configured, services have started and the Tally Manager has been logged on. 7.3.2. Precinct tabulation Not Applicable. Ballots tabulated centrally. 7.4. Integration with other systems and Calvoter 7.4.1. Aggregator Application The Aggregator Application integrates election results between the MTS system with the Tally System. System setup is described in Section 4.2. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 41 The Aggregator Application is a command line driven application. Below are the basic commands to aggregate totals. For help on available commands and syntax type: ./aggregate -help The mts_summary.dat (MTS results file) and vsap.json (Tally System results file) that need to be aggregated are put into the “inputs” folder. These files are copied using removable digital media. Type the following to start aggregating the totals: ./aggregate The following result files are put into the output and archive folder. ● Mts_summary.dat - New aggregated results in MTS result file format ● Press.html - Semi-Official Results Press Bulletin ● Lna.html - Logic and Accuracy Results Report. Contains a matrix of counter and value ● Vsap.json - New aggregated results in Tally System results file format To create a version of Final Official Press Bulletin enter the following command. ./aggregate -final=true 7.4.2. Calvoter Los Angeles County’s MTS and ECBMS complies with election night vote reporting using electronic files. These reports are put in the the Secretary of State CalVoter II system sftp. The CalVoter II system retrieve the report, transfer the data to the database, and process the information into the elections reporting system. For every major election, starting E-43, Los Angeles County partakes in the Automated County Certification process to verify integration between both systems are in sync. Los Angeles County also participates in at least two weekly load test after certification. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 42 8. OFFICIAL CANVASS AND POST-ELECTION PROCEDURES Except as noted in Section 8.1 below, Los Angeles County will comply with the Use Procedures approved by the Secretary of State for the InkaVote Optical Scan Voting System. 8.1. Canvassing Ballots Voted on the Audio Ballot Booth The audio ballot slips cast by voters using the Audio Ballot Booth will be reproduced onto InkaVote ballot cards for counting on the card readers of the InkaVote Optical Scan Voting System. This process will take place during the official canvass and will follow California Elections Code §15208 and 15210 that govern the segregation and duplication of ballots. 8.2. Canvassing VSAP VBM Ballots 8.2.1. In-house VBM Remake Application The VBM Remake is a tool designed to assist in the process of remaking overseas, faxed or damaged VBM ballots prior to tabulation. The VBM Remake enables Canvass staff to print full-face ballots using blank ballot stock. The marking of the ballots are done manually by staff and verified by a QC team. An overseas voter receives their sample ballot via email or through the postal service. If the voter returns the ballot by fax or on a printed sample the ballot the ballot must be remade to be able to be processed by the Tally System. Ballots can be damaged at many points in the voting process. Voters may damage the ballots prior to returning them to the Registrar Recorder’s office or the ballots may be damaged during the return mail process. Torn, stained or shredded ballots are not able to go through the Tally System and each one must be remade. The following are the VBM Ballot Remake Application steps: 1. A ballot group or ballot style is entered or scanned into the system. 2. The image of the ballot is displayed. 3. Computer operator verifies they ballot is correct. 4. Computer operator clicks print ballot. 5. The system prints a remake id on the ballot page(s). 6. Computer operator writes the remake id on the original ballot. 7. The printed remake and original ballot are sent to the hand marking operation. 8. Remake staff marks the ballot matching the voter’s intent using a black pen. 9. Original and remake ballot is sent to QC. 10. QC checks that the selections match the original. 11. Original is filed. 12. Remake ballots are boxed and ready for Tally. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 43 8.2.2. Tally System Reprocess Ballots User navigates to Manage > Reprocess, clicks the Reprocess button and reprocesses the SBR records through Refiner. Reprocessing archives all “old” CVRs, exports all outstacks, and then sends all SBR records back through the refining process. Figure: Reprocess Screen 8.2.3. In-house Ballot Storage Application Ballot are stored in boxes that hold approximately 1,200 ballots. After processed VBM ballots have been put into a box they are sealed with a serialized tamper evident seal with a unique ID. The box is moved to a staging area where the box is ready for ballot storage. The Ballot Storage System tracks ballot boxes at two scan points. One is in the Tally room after ballots have been processed and the other is where the ballots are stored. 8.2.3.1. Ballot Storage Scan Point 1 During VBM Tally, processing a box lead sheet is run when starting an empty box. This box lead sheet tells VBM Tally that all the ballots after the box lead sheet are in that box id. The box lead sheet is a sticker label and the output runner will stick the label on the outside of the box so it can be scanned. Scan Point 1 is a VBM ballot box check point that tracks which boxes have been completed. To log this information, using the Ballot Storage Application, the ballot storage operator scans the box id 1d barcode. The Ballot Storage operator verifies the box id on the box matches what is on the screen. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 44 8.2.3.2. Ballot Storage Scan Point 2 Once the processed VBM ballot box has been scanned at scan point 1 they are moved to a ballot storage area. Using the Ballot Storage Application, the Ballot Storage operator scans the 1d barcode on the box and scans or enters the location of ballot box. The location is defined by Room, Section and Shelf. 8.2.3.3. Finding a ballot Once a VBM ballot box has been scanned with a location, the Ballot Storage system is able to locate the ballot box or ballot: ● Select the ballots by precinct or box id ● Print a ballot box report ● Find the box using the location on the report ● Verify the seal on the box is untampered and the number matches the log on the box ● Find the ballots by the ballot ID printed on the ballot ● Check off the ballots on the report that have been located ● Once all the ballots have been found seal the box with a new serialized tamper evident seal ● Sign, date and write the serial number on the box 8.3. Canvassing precinct returns Los Angeles County will comply with the Use Procedures approved by the Secretary of State for the InkaVote Optical Scan Voting System with respect to processing Canvass precinct returns. 8.4. Canvassing provisional ballots Los Angeles County will comply with the Use Procedures approved by the Secretary of State for the InkaVote Optical Scan Voting System with respect to processing Canvass provisional ballots. 8.5. Canvassing write-in votes Los Angeles County will comply with the Use Procedures approved by the Secretary of State for the InkaVote Optical Scan Voting System with respect to processing Write-In ballots. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 45 For VBM ballots, contests that allow for write-in candidates will have a vote position for the voters write-in candidate(s). Through the Tally System Ballot Viewer, Canvass is able to view all the write-in selections and validate the voter’s intent. The Ballot Viewer is a browsing tool and does not update CVR records in the Tally System. Votes for qualified write-in candidates are tallied by using manual scoring sheets and reported as an addendum report. Open the Ballot Viewer and click Home in the main menu. Select Write-In in the Filter drop down menu. Write-in contests are tabulated by contest. Select the contest you would like to review. To start the write-in process click the F ind Ballots button. Figure: Ballot Viewer After the ballot search, save the search results. Name the ballot search and click Save Results. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 46 Figure: Ballot Search Results Screen To start reviewing a write-in saved search click Saved Searches in the main menu. A list of the available saved searches will display. Click the S aved Search for review. Figure: Ballot Saved Search Screen A list of VBM ballots will display in Ballot ID order. Select a ballot to view. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 47 Figure: Write-in Saved Search Screen The ballot viewer will display the ballot and the write-in is ready to be reviewed and manually tabulated. Once the ballot is reviewed, click the Mark Reviewed button. Setting the marked reviewed flag will signify the contest on this ballot has been reviewed, preventing the ballot to be reviewed twice. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 48 Figure: Write-in Ballot Review Screen Once the ballot has been marked as reviewed a status Reviewed will display. Click Next Unreviewed to continue to the next ballot. Reviews can be done multiple times for a contest. Simply start the process over and give the saved search a unique name. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 49 Figure: Write-in Ballot Review Screen with Reviewed Contest 8.6. 1% Manual Recount Procedures Los Angeles County will comply with the Use Procedures approved by the Secretary of State for the InkaVote Optical Scan Voting System with respect to 1% manual recount procedures. For the purpose of validating the accuracy of the computer count a public manual recount of VBM ballots will be conducted. The ballots for the VSAP VBM manual recount will be determined by a random selection of processed ballot batches (boxes). The number of batches selected is based on the number of ballots in a batch and representing at least 1% of the total vbm ballots cast. Additional batches, as necessary, shall be selected by the elections official and manually recounted for any office or ballot measure not recounted in the original sample. Batches selected at random pursuant to Elections Code section 15360 shall be chosen by an individual who is designated by the responsible elections official and who is not the same person responsible for programming the ballot counting computer program. Selected batches shall not be revealed to computer programming personnel until the semi-official VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 50 count is complete. The manual tally is a public process, with the official conducting the election providing at least a five-day public notice of the time and place of the manual tally and of the time and place of the selection of batches subject to the public manual tally prior to conducting the selection and tally. The manual recount procedure is conducted by two people and may be observed. All the original ballots will be reviewed by contest and recorded on tally sheets. 1. Tally board is prepared with ballots from a batch and tally sheets. 2. For each contest the selection from every ballot is read aloud. 3. The other party records each vote on the tally sheet with one pencil stroke per vote. Includes any under or voter voted contests. 4. The total of all pencil strokes for each candidate is counted and written into the proper box on the tally sheet. The official conducting the election shall include a report on the results of the 1 percent manual tally in the certification of the official canvass of the vote. This report shall identify any discrepancies between the machine count and the manual tally and a description of how each of these discrepancies was resolved. 8.7. Handling ballot exceptions VBM ballot extraction begins e-14. During this process QC Staff reviews each ballot and separates good ballots with ones that need further review. QC tasks include: ● Remove any portion of the ballot stub, such as an incompletely detached perforation, that remains attached to a ballot card. ● Jog cards for static electricity removal. ● Inspect the ballots for tears, folds, or damage. ● Damaged ballots are to be placed in the ballot remake box. ● Inspect the ballots for any identifying marks, such as a person’s name, as instructed. ● Ballots with identifying marks are placed in the ballot remake box. ● Inspect the marks on all ballots as instructed. ● When all ballots have been inspected align them so the printed black corner is in the upper right corner. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 51 Figure: Ballot Extraction Process Diagram Tally System vote mark detector is an operation that determines if the vote mark is selected or not. Vote mark detector depends on the Tally Layout Definition File (TLDF) to inform how it will be run. The TLDF also lists out the vote marks that need to be processed by ballot style id. When calculating whether a vote mark should be considered as selected or not, the number of pixels counted is compared against this total number of pixels. The target zone of is 113 x 113 pixels with a total of 12,769 pixels, each pixel accounts for about 0.0078% of the total target area. The current configuration for the percentage threshold is 8.1%-100% of the target area. This amounts to at least 1,034px of the 12,769px. If there are more than that many pixels, then the vote mark is counted as a selection. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 52 8.8. Post-election logic and accuracy testing A Logic and Accuracy Board shall be appointed by the responsible elections official and, insofar as is practicable, shall be comprised of the same persons prior to, during, and after the election. The Board shall have the following duties: ● Receive from the elections official all required test materials and take steps to ensure the security of said materials prior to, during, and after the election, except when the materials are properly in the possession of one of the other boards or elections officials as required by these procedures. ● Verify the correctness of the logic and accuracy test ballot images. This verification shall also be required for any of said material that must be replaced. ● Observe the performance and verify results of all required tests. ● Note any discrepancies and problems and affirm their resolution or correction. ● Deliver into the custody of the elections official all required test materials and printed output. ● Certify to the performance of each of the above-prescribed duties as well as those otherwise established by the procedures; provided that all members of the Board shall sign the appropriate certificate or certificates. Final pre-election certification shall be made to the Secretary of State no less than seven days before each statewide election. The responsible elections official shall make this certification based on the Logic and Accuracy Board's certification of successful testing. In the event an amendment to the ballot counting program is required following this certification, the elections official must immediately re-certify to the Secretary of State. 8.9. Final reporting of official canvass Any delays in Election night's semi-official canvass reporting due to hardware, software, environmental, or human causes which result in failure to report results to the Secretary of State at least every two hours shall be reported to her or him by the 28th day following the election. The responsible elections official may also report other delays in the processing of ballots, as he or she deems appropriate. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 53 8.10. Backup and retention of election material 8.10.1. Archive Election Navigate to Archive > Archive Election and click on the Archive Election button. This creates an archive of all the important files for any particular election. The archive can be found in the /opt/mounts/election_archive directory. Figure: Creating an election archive 8.10.2. Run reports After the election has been archived, you may navigate to Tabulate/Reports and generate reports. Click the Generate Reports button and/or the Generate Final Reports button. To view the report, click the newly created Tabulation ID link. 8.10.3. Export 1. From Tally Manager Ballot Viewer, go to the M anage tab and select Exporter from the menu drop-down to display the Export page. 2. Click the Export button to export all active ballots, all excluded ballots, and all ballot boxes. See image 2. 3. An Export Complete message will be displayed with a successful export. 4. The exported files can be found in /opt/mounts/tally_export. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 54 Figure: Exporting ballots 9. MANUAL RECOUNT PROCEDURES For the purpose of validating the accuracy of the computer count, within fifteen days after every election at which the InkaVote system was used, a public manual recount of the ballots cast in at least one percent of the precincts, chosen at random, shall be conducted. Los Angeles County will comply with the Use Procedures approved by the Secretary of State for the InkaVote Optical Scan Voting System. VSAP VBM Ballots The VSAP VBM ballot manual recount procedure is conducted by two people and may be observed. All the original ballots will be reviewed by precinct and contest and recorded on tally sheets. 1. Tally board is prepared with ballots from a batch and tally sheets. 2. For each contest the selection from every ballot is read aloud. 3. The other party records each vote on the tally sheet with one pencil stroke per vote. Includes any under or voter voted contests. 4. The total of all pencil strokes for each candidate is counted and written into the proper box on the tally sheet. 10. SECURITY Los Angeles County will comply with the Use Procedures approved by the Secretary of State for the InkaVote Optical Scan Voting System. 10.1. Physical security of system and components Network - The network domain that hosts election definition and ballot layout functions is physically separate from Tally System and does not have interconnectivity of traffic between domains. Data is transferred through a manual process under human control. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 55 The Tally System is hosted on a separate network domain that is not physically connected to any other County LAN and no physical interconnections exist between the Tally System and any other network or end-point device that connects to the Internet. Protective Barrier - The placement and design of the tabulation room must allow for a secure environment that aims to deter or delay any attempt to disrupt tabulation operations while providing a means for interested parties to observe tally activities. Rack-mounted Equipment - Hardware components such as scanners, servers and network devices must be housed in locked enclosures that contain racks for servers, network switches, power distribution units, and other components or peripherals. Serialized tamper-evident seals are used on removable panels. Removal and replacement of seals must be witnessed by at least two election staff members and documented using a log with signatures by both parties. Access Control - Entry and Exit doors must be protected by an electronic key card access system. Entry and exit must be automatically logged with identity, date, time, and door number recorded for each instance. The key card system must be operated and maintained by a designated team and access shall only be granted when authorized by designated managers. Policies and procedures for access control to the tabulation room must be defined and implemented. Surveillance Cameras - Surveillance cameras must be installed to record activity (24x7) in the tabulation room, including entry and exit events. The cameras must be installed in locations that are designed to minimize or deter tampering. Cameras can reduce the number of staff required to monitor the room. Environmental - A dedicated HVAC system that cools, heats, and ventilates the tabulation room and provides an optimum operating environment for computers and other electronic components used by the Tally System must be installed and fully operational. Alarm and Intrusion Detection System (IDS) - An alarm and IDS must be installed as an important countermeasure against emergency conditions or attacks that happen after business hours. It’s main purpose is to work as a force multiplier to allow for more efficient use of staffing by reducing the number of security personnel required to patrol or monitor the tabulation room. Key to and effective alarm and IDS is the implementation of an incident response process with a response force nearby ready to act. Trained Security Staff - Another measure that aims to deter potential attacks are stationing of trained security staff (Los Angeles uses Deputy Sheriffs) in strategic points and perimeter of the tally operations area. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 56 10.2. Logical security of system and components 10.2.1. Essential and non-essential services and ports Unused USB data ports are covered with serialized tamper evident seals on the VSAP Tally servers and IBML 6000 scanners. The serialized tamper evident seals are manually logged with an operator signature, seal number, location, date and time. Description\Qty Function OS\Version USB Physical Security Ports Control Ibml ImageTrac Ballot scan and Ibml 2 Scanner components COTS Scanner (1)* conversion to Software are housed in locked digital image Suite cabinet. Serialized tamper evident seals are placed on removable panels Ibml ImageTrac Image Capture Windows 10 10 Server is locked in COTS Server (1) Software Suite Enterprise scanner cabinet. and Database and MS Unused physical ports SQL 2012 are protected by port locks. COTS Server CIFS File CentOS 10 Server is rack-mounted Class x86_64 Server 7.4-1708 within locked Computer (1) enclosure. Unused ports are protected by port locks. COTS Server Tally Servers CentOS 10 Server is rack-mounted Class x86_64 7.4-1708 within locked Computer (2) ** enclosure. Unused ports are protected by port locks. * The number of scanners used for an election will vary between 1 to 6 scanners. ** The number of servers used for an election will vary and may require more than 2 servers. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 57 Note: Locks that are either built-in or bundled with COTS hardware are designed to deter access to equipment by unauthorized personnel. A maintenance log that records date, time, maintenance action taken, and name of election staff who authorized access (along with signatures of both technician and election staff) must be maintained to document and record maintenance activities. 10.2.2. User-level security The Tally System has numerous access controls to deter unwanted users from accessing the system. There are three role types in the Tally System. The first role is the Linux administrator. The Linux administrator can configure the system, setup new users, set up configuration files, configure the Tally System, and view logs. Second is the application admin. The application administrator can manage running services in the Tally System, tabulate elections, view errors, and conduct all necessary election night operations. Finally is the view-only user who can look at the Tally Manager interface, but can not physically affect the system. The Tally System is only accessible to individuals who have a username and password. Usernames and passwords are managed via process by the system administrator. User passwords are never stored in clear text or reversable formats. There is a system tool for generating password entries. All user passwords are stored in PBKDF2. The system also uses password internally for authenticating service to service calls. These are in the form of a shared secret that is a long random value. Because this value must be used by services it must be stored in plain text in the production configurations. These files are protected via file permissions. 10.2.3. Anti-virus protection Anti-virus protection will not be used in Tally System servers due to negative impact on system performance and stability. The build and deploy process will ensure installation of the latest patches to the OS and other COTS software. Prior to system installation, a list of known vulnerabilities from trusted partners will be reviewed to determine patch levels that must be applied to remediate these vulnerabilities. The risk of intrusion from threats and attack vectors has been classified as ‘LOW’ with strong physical controls, isolation of the location of the Tally System, and trusted staff performing installation and system administration functions forming a ring of managerial controls around the air-gapped environment. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 58 10.2.4. Procedures verifying, checking, and installing essential updates and changes Changes are primarily for installing critical updates to operating system, anti-virus protection or other third-party elements related to security and error correction. 10.2.4.1. Audit records for the changes showing what, when, who, and why Each Tally service identifies events to logs on the file system. The logs are preserved for auditing. Users with server administrator permission can access logs on the services server at /opt/mounts/tally_logs (the location is specified in the services-docker-compose.yml file). Users with server administrator permission can access logs on the Providers server at /opt/mounts/kaa (the location is specified in the providers-docker-compose.yml file). Log file names appear as follows: [service][logfileidnumber].json. The system generates one log file per service instance and writes all logs for that service instance into that single file. Each entry is written with a severity (info, warn, error, fatal), along with a type (see previous section), A message, and an action. Each log entry is a JSON formatted string on a single line to allow for easy parsing. The file itself is not a JSON file which makes appending more efficient. Although user logs are not split out from system logs, almost all user related log entries will be in the Tally System and Auth service logs. Logs created by receive, recognize, refine, outstack, will ether be ballot level logs or system logs. Any ballot level issue will also be reported via an outstack record which will be visible in the ballot viewer. 10.2.4.2. Installation procedures for those updates which would normally be installed using an internet connection The Tally System is hosted on a separate network domain that is not physically connected to any other County LAN and has no physical interconnections existing between the Tally System and any other network or end-point device that connects to the Internet. The Aggregator Application runs on a standalone COTS PC and is physically separated from the Tally System. Data between the two systems is transferred through a manual process under human control and performed by trusted staff. Installation of updates is performed through a set of manual procedures overseen by trusted election managers. Installation activities VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 59 are documented with at least two staff members performing updates. Documentation includes, date-time of update, person who performed activity, person who witnessed the activity, and certification that update installed was previously approved by the Secretary of State. 10.2.4.3. Acceptance testing after the installation. Los Angeles County will comply with the Use Procedures approved by the Secretary of State for the InkaVote Plus PBR Voting System with respect to PBR unit acceptance testing after installation and configuration. 10.3. Security procedures for central processing Los Angeles County shall follow the following security procedures to ensure the protection of the election tally process from intentional manipulation, fraudulent manipulation, fraudulent and intentional manipulation, malicious mischief, accidents, and errors. All public access is limited to viewing only. All visitors are required to check in and be escorted by appropriate staff. 10.3.1. Facility access procedures The Tally System for central processing resides in a secure facility with 24-hour security and video surveillance, and a key card system controlling access to doors within the facility. During non-business hours, the main access doors to the building are locked and require an ID badge with a keycard to open the doors. All individuals entering the building during non-business hours must check in with the Security Desk in the lobby of the facility. The key card system supports several access types that can control entry through doors to the various operational areas of the facility. The Tally System is located in a secure room within the facility and keycard access to the doors of the facility is limited to only those personnel who are assigned to work or supervise within the room. A list of people who have keycard access to the secure Tally room can be provided at any time. The keycard system does keep a log of who is accessing, or attempting to access, a door at any given time. The Tally system operates on an isolated, air-gapped network in the secure room that is not connected to the local area network, so it is impossible to gain access to the Tally system from the Internet, the wide area network, or the local area network. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 60 10.3.2. VBM ballot procedures The handling and storing of VBM ballots are all performed at the Los Angeles County Registrar-Recorder County Clerk headquarters. Only employees of RRCC may have custody of any VBM ballots or report logs. Below are the following procedural security measures taken: ● VBM ballots are processed and stored in climate-controlled environments with key card access. Storage areas contain a racking location system and VBM ballots are not left on the floor. ● VBM ballots are stored in boxes that are logged and sealed with serialized tamper evident seals ● VBM ballot boxes are logged and signed with staffs’ initials, date and time ● VBM ballot boxes moved between operations are done by two operations staff ● After processing ballot boxes are scanned with a location for traceability. See section 8.2.2. ● Tally system captures the box id for all VBM ballots ● Public access to processing VBM ballots are limited to viewing only ● Integrity of all serialized tamper evident seals are verified before removing 10.3.3. Election night procedures Los Angeles County will comply with the Use Procedures approved by the Secretary of State for the InkaVote Plus PBR Voting System with respect to election night procedures. 10.4. Security procedures for polling places As the PBR devices will not be used to officially record or tabulate votes, no additional security measures are applicable. 10.5. Audit trails Election audit trails are vital to validating the accuracy of election results. All Tally system components create an audit log anytime the system is accessed or data is changed. Audit logs can be opened and printed to hard copy if needed. Detailed description of the setup, configuration and layout of the audit log can be found in the following documents: ● Tally Sy stem Setup Document VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 61 ● Tally System Errors and Logging Document ● Application Logic Design and Specification 11. Biennial Hardware Certification and Notification EC § 19220 requires jurisdictions to examine voting systems every two years and certify the results to the Secretary of State. Describe detailed procedures for performing the examination and certifying the results to the Secretary of State. Los Angeles County will comply with the Use Procedures approved by the Secretary of State for the InkaVote Optical Scan Voting System and the InkaVote Plus PBR Voting System 1.10. The Tally System will comply to the following: 11.1. Notification For each statewide election, the responsible county elections official shall cause to be prepared a list, including quantities, of all equipment to be used to tabulate votes during the semi-official and official canvass. 11.2. Certification of logic and accuracy testing Seven days before each statewide or special election, the elections official shall certify to the Secretary of State the results of the logic tests as well as the accurate functioning of all ballot counting equipment. This certification shall also affirm the use of the same equipment for pre-election testing and for semi-official and official vote canvasses. In the event of a change to the ballot tally program occurring after this certification, an amended certificate shall be submitted no later than the day before the election. In the event any equipment is repaired, altered or replaced following this certification and prior to completion of the official canvass, an amended certification of logic and accuracy testing and a revised list of equipment used must be submitted to the Secretary of State not later than submission of official canvass results. 11.3. Logic and Accuracy Board A Logic and Accuracy Board shall be appointed by the responsible elections official and, insofar as is practicable, shall be comprised of the same persons prior to, during, and after the election. The Board shall have the following duties: VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 62 ● Receive from the elections official all required test materials and take steps to ensure the security of said materials prior to, during, and after the election, except when the materials are properly in the possession of one of the other boards or elections officials as required by these procedures. ● Verify the correctness of the logic and accuracy test ballot images. This verification shall also be required for any of said material that must be replaced. ● Observe the performance and verify results of all required tests. ● Note any discrepancies and problems and affirm their resolution or correction. ● Deliver into the custody of the elections official all required test materials and printed output. ● Certify to the performance of each of the above-prescribed duties as well as those otherwise established by the procedures; provided that all members of the Board shall sign the appropriate certificate or certificates. Final pre-election certification shall be made to the Secretary of State no less than seven days before each statewide election. The responsible elections official shall make this certification based on the Logic and Accuracy Board's certification of successful testing. In the event an amendment to the ballot counting program is required following this certification, the elections official must immediately re-certify to the Secretary of State. 11.4. Election Night and Post-Election Reporting Any delays in election night's semi-official canvass reporting due to hardware, software, environmental, or human causes which result in failure to report results to the Secretary of State, at least every two hours, shall be reported to her or him by the 28th day following the election. The responsible elections official may also report other delays in the processing of ballots, as he or she deems appropriate. VSAP Tally System Version 1.0 Los Angeles County 2018 | Blended Use Procedures Page 63