NIST Voting Program

Reviews
NIST Voting Program Barbara Guttman 12/6/07 www.vote.nist.gov NIST “Help America Vote Act” Responsibilities Chair Technical Guidelines Development Committee (TGDC)  Provide technical support to TGDC in the development of voluntary voting system guidelines including  Recommend independent labs to the EAC for accreditation  TGDC Background  Created by HAVA    15 members, different disciplines Chaired by NIST Director NIST performs research and technical support  Delivers recommendations to the EAC Voting Program Activities Update Page 3 NIST/TGDC Committee Structure & Coordination  TGDC resolution (July ‘04) established 3 subcommittees:  Security and Transparency (STS)  Human Factors and Privacy (HFP)  Core Requirements and Testing (CRT) Each subcommittee has NIST staff assigned to it  NIST & the TGDC    NIST performs research for the TGDC TGDC makes recommendations to the EAC NIST does the technical writing of the VVSG Voting Program Activities Update Page 5 NIST/TGDC Activities   July 2004: 1st plenary session of TGDC May 2005: Provided initial recommendations for voting system guidelines (VVSG 2005) Sep 2007: Provided next set of recommendations for voting system guidelines (Next VVSG)  Why are there two versions of the VVSG?  HAVA required initial recommendations from the TGDC in 9 months  VVGS 2005 limited due to timeframe – incremental improvement to the 2002 VSS   There was a need to develop comprehensive, updated requirements for voting systems Therefore, TGDC developed two versions:   VVSG 2005 is an update of the VSS 2002 Next VVSG is a complete re-write Page 7 Voting Program Activities Update What is in the Next VVSG?  Complete re-write of VVSG 2005 in all areas  Usability and Accessibility  Security  Core Requirements Voting Program Activities Update Page 8 VVSG Major Re-Organization Part 1: Equipment Requirements Part 2: Documentation Requirements Part 3: Testing Requirements in Parts 1 and 2 reference general test methods in Part 3 Voting Program Activities Update Page 9 Walk Through of Requirements  Human Factors & Privacy  Usability, Accessibility, Other  Security & Transparency  SI, Innovation Class, IVVR, Other Reliability, COTS, Other Page 10  Core Requirements & Testing  Voting Program Activities Update Software Independence  Voting systems must be SI    Accuracy of the election must not rely exclusively on the accuracy of the voting system software Accuracy of the system’s electronic records will be able to be independently audited against an independent voter-verified record (IVVR) Systems that do this currently are paper-based e.g., optical scan, VVPAT Voting Program Activities Update Page 11 Innovation Class  Next VVSG includes an Innovative Class   The VVSG will allow for developers to create new and innovative, possibly paperless, voting system approaches that would still be independently auditable and conform to the next VVSG This may include newer, cryptographic-based systems that potentially promise greater usability and accessibility as well as security Voting Program Activities Update Page 12 Other Security      Radio-Frequency (RF) wireless is no longer permitted for use on voting systems Requirements for test labs to conduct open-ended vulnerability testing on voting systems to search for vulnerabilities Requirements to digitally sign electronic records for integrity and to identify each record by machine and election Requirements for all software to be digitally signed and verified before being permitted to load or run on voting system Other security areas: access control, auditing, event logging, and physical security Voting Program Activities Update Page 13 Reliability Benchmarks  Voting system quality, reliability (MTBF), and accuracy requirements updated     Replaced MTBF method with volume testing (based on CA’s) Worked with NASED to develop number and types of allowed failures To improve voting system design and testing techniques To ensure that voting systems are robust and work properly Voting Program Activities Update Page 14 COTS  COTS testing requirements re-written    To make clearer whether to exclude certain COTS products from in-depth source code reviews Definition of unmodified COTS narrowed Modified COTS grouped into several categories, each with its own testing requirements Page 15 Voting Program Activities Update Other Core Requirements  Conventions for software coding were examined  E.g., requiring software languages that contain improved integrity and security constructs   To promote quality systems, requirements for vendors to comply with ISO 9000/9001 Updated electrical, clarified requirements for all voting activities Page 16 Voting Program Activities Update Discussion Voting Program Activities Update Page 17

Related docs
NIST Voting Program Activities Update
Views: 0  |  Downloads: 0
NIST
Views: 12  |  Downloads: 0
NIST Handbook NVLAP Voting System Testing
Views: 25  |  Downloads: 0
NIST VVSG Template
Views: 4  |  Downloads: 0
Planning at NIST
Views: 22  |  Downloads: 2
NIST Update Bill Jeffrey.ppt
Views: 1  |  Downloads: 0
NIST THREE-YEAR PROGRAMMATIC PLAN
Views: 8  |  Downloads: 2
Improving Safety at NIST
Views: 2  |  Downloads: 1
premium docs
Other docs by delontewest De...
Partnership disputes Arbitration
Views: 197  |  Downloads: 2
Extension of Commercial Lease
Views: 252  |  Downloads: 3
Natural fathers application
Views: 215  |  Downloads: 0
Acknowledgment and consent of lessee
Views: 251  |  Downloads: 1
Death retirement or withdrawal of partner
Views: 292  |  Downloads: 1
Sample Executive Summary EcoClear Inc
Views: 233  |  Downloads: 0
Civil Rights Act info
Views: 198  |  Downloads: 1
press-release-template
Views: 843  |  Downloads: 41
4mega
Views: 133  |  Downloads: 0
ASSIGNMENT OF ASSETS
Views: 336  |  Downloads: 3
Biometrics_Study
Views: 180  |  Downloads: 16