Skip the navigation

GAO questions progress on e-voting standards

Questions about security, accuracy likely to continue into the '06 elections

By Grant Gross
October 24, 2005 12:00 PM ET

IDG News Service - Questions about the security and accuracy of electronic voting systems are likely to continue into the 2006 national elections, because the U.S. government has not yet completed work on electronic voting guidelines, according to a new government report.
With lingering concerns about the security of e-voting systems, the U.S. Election Assistance Commission (EAC) needs to define security policies and set up a machine-certification program to help state and local election officials use e-voting equipment, according to a report issued Friday by the U.S. Government Accountability Office (GAO).
"Until these efforts are completed, there is a risk that many state and local jurisdictions will rely on voting systems that were not developed, acquired, tested, operated or managed in accordance with rigorous security and reliability standards -- potentially affecting the reliability of future elections and voter confidence in the accuracy of the vote count," the GAO report said.
The EAC, established with the Help America Vote Act passed by Congress in 2002, is working on several initiatives to help state and local governments improve their management of e-voting systems, the GAO said. The EAC is working on security and reliability standards and on programs to certify voting machines and accredit independent laboratories to test e-voting systems, the GAO said. But those efforts aren't finished and are "unlikely to have a significant effect in the 2006 federal election cycle," the report said.
The EAC "significantly expanded" the security system of proposed voluntary voting system guidelines, the EAC said in response to the GAO report. Those guidelines include a requirement that e-voting machine vendors submit software to the National Software Reference Library, a software repository with which voting officials could examine software for exploits.
"GAO asserted that electronic voting systems must be secure and reliable, and EAC agrees," the EAC statement said. "Security has always been a top priority at EAC, and we have already made significant progress on GAO's recommendations."
The EAC and the National Institute of Standards and Technology (NIST) are developing a vulnerability analysis of e-voting systems, the statement said.
The EAC also questioned the GAO's reference to security and reliability questions about e-voting systems. The GAO report talks about security and reliability problems experienced, but it "does not provide a context of the pervasiveness or relative obscurity of these issues," the EAC wrote in a letter signed by EAC Chairwoman Gracia Hillman and Vice Chairman Paul DeGregorio.
The GAO report relies on documents produced by other people, but the agency didn't substantiate those reports of security and reliability problems, the

Reprinted with permission from IDG.net. Story copyright 2010 International Data Group. All rights reserved.
Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Gov't Legislation/Regulation White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
All Gov't Legislation/Regulation White Papers
Gov't Legislation/Regulation Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Gov't Legislation/Regulation Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs