Risk and compliances New
1
Final Risk Assessment and Compliance Report
Name
University of Maryland Global Campus
CCA 610: Cloud Services and Technologies
Professor Richard Utter
November 23, 2021
2
Executive Summary
Cloud computing is an alternative way for BallotOnline to save cost by moving the on-premises
data center to the cloud. However, there are some risks with moving to the cloud. The Final Risk
Assessment and Compliance Report explains the threats and how BallotOnline needs to comply with
geographic laws, election laws, data protection laws, and policies. This assessment is written for the
executives of BallotOnline. The Final Risk Assessment and Compliance Report is a careful evaluation
that details all the possible risks by analyzing and using a risk matrix to explain how the risk can be
avoided, mitigated, or accepted. Out of the top ten items listed as risks, most were unlikely to happen; and
the risk that was likely to occur had tangible ways to mitigate, avoid or transfer the risk. Most risks for the
cloud data center are the same as using an on-premises data center.
The risk management guidelines list standards that BallotOnline must comply with to ensure the
customers' data is safe. The standards or laws that will be used are the National Institute of Standards and
Technology, General Data Protection Regulation, and Cybersecurity Framework Election Infrastructure
Profile 8310. The General Data Protection Regulation is a European Union law, but it can be used to
protect all BallotOnline voters worldwide. This assessment covers the importance of protecting the voters’
data to prevent legal actions or fines due to potential privacy issues. There are relevant security issues that
apply to both on-premises and cloud-based datacenter. Both the security issues and the mitigation
methods are discussed in this assessment. Since BallotOnline will provide voting access to voters
worldwide, BallotOnline must comply with local laws and regulations to protect the company from fines
and penalties. The geographic, election industry, and data compliance requirements are discussed and
reviewed. This assessment lists action plans and proposes a compliance program proposal to prevent
violating any laws or regulations. After meticulously evaluating all the risks; a governance, risk, and
compliance roadmap is suggested as the official policy to mitigate all the risks with moving BallotOnline
to the cloud.
3
Risk Analysis
BallotOnline is taking some risks by moving to the cloud. The risks of moving data to the cloud
are similar to those of having an on-premises data center. However, the benefits outweigh the potential
risks. BallotOnline must work with the Cloud Service Provider (CSP) and within the regulations of the
local country to mitigate those risks.
Risks can be listed in two main areas: external risks and internal risks. An external risk could
come from a threat outside of the company. Examples of external risks are hackers trying to steal or
destroy voter data, an internet outage, a power outage, a fire, or a flood. An internal risk could come from
inside the company. Examples of internal risks are insider threat hackers, untrained programmers, or data
loss. These are the same threats that could affect BallotOnline while using an on-premise data center.
BallotOnline can face the same risks at a lesser cost and have greater reach using a CSP. Table 1 has the
risk matrix based on the significant threats to BallotOnline.
Risk Threat Result Risk Detail Odds Impact Risk Score Response Action Type
Response Actions
Fire Accidental or environmental
Equipment damaged and an outage
No fire suppression system or system cannot stop the fire
Unlikel y
Major Unacceptable Risk: Extremely High
Mitigate Disaster recovery/failover
Loss of power
Accidental or environmental
Outage Lack of access to voter information
Unlikel y
Major Unacceptable Risk: Extremely High
Mitigate Disaster recovery/failover
Programming error
Training Software or routing stop working
Voting software does not work or is not accessible
Likely Major Unacceptable Risk: Extremely High
Mitigate This will be mitigated with training and testing
Passwords released
Adversarial outsider (e.g., hacker)
An unauthorized person gains access to BallotOnline
An unauthorized person can steal data or BallotOnline voting software
Unlikel y
Major Unacceptable Risk: Extremely High
Avoid All logins will be with PKI certs. No passwords are allowed.
Denial of Service
Adversarial outsider (e.g., hacker)
Outage Voters will not be able to vote. Admin will not be able to access the system
Unlikel y
Moderate Acceptable Risk: Medium
Transfer Failover
Worldwide internet outage
Accidental or environmental
Outage Voters will not be able to vote. Admin will not be able to access the system
Unlikel y
Minor Acceptable Risk: Low
Accept Wait for the internet to recover
Internet outage at Cloud Provider
Accidental or environmental
Outage Voters will not be able to vote. Admin will not be able to access the system
Unlikel y
Minor Acceptable Risk: Low
Transfer Disaster recovery/failover. Also requiring the Cloud Provider to have different ISPs.
Data Breach Adversarial outsider (e.g., hacker)
Stolen data with PII released to the public
Report breach to GDPR and voters
Likely Major Unacceptable Risk: Extremely High
Mitigate Encrypt all data with strong encryption and PKI
Data Loss Technological failure
Voter data lost No backups of the data Unlikel y
Moderate Acceptable Risk: Low
Avoid Backup all files securely in three locations
Custom Software too complex
Training Admin slow to move to the cloud
The admins do not have a complete understanding of how to move to the cloud
Very Likely
Major Unacceptable Risk: Extremely High
Mitigate Training
Table 1
The most important thing for BallotOnline is to protect the voters’ data from internal and external
risks. The data must remain unaltered to ensure it is correct and must be encrypted. If BallotOnline lost
the voters’ data, they would have to pay fines, and voters would lose confidence in their system.
4
Risk Management Guidelines
For BallotOnline to abide by local laws and cybersecurity governance, it must use cybersecurity
standards to reduce the risks for the voters. BallotOnline should consider at least two cybersecurity
standards as the baseline. The first standard for BallotOnline is the National Institute of Standards and
Technology (NIST) Cybersecurity Framework. The second baseline for security is General Data
Protection Regulation (GDPR).
NIST was one of the original contributors to the United States cybersecurity industry standards
for the cloud and made guidelines for protecting the use of computers for voting. NIST has an adaptive,
risk-based framework that works in every step of an election cycle: the pre-election, election day, and
post-election activities. NIST calls this the Cybersecurity Framework Election Infrastructure Profile
(NISTIR) 8310. The NISTIR 8310 draws upon the experience of election participants and cybersecurity
professionals worldwide to offer a way to secure all elements of election technology.
The GDPR has some of the strictest online security and privacy law in the world. Since
BallotOnline is worldwide, using GDPR as a baseline for cloud election security would abide by the laws
in the European Union (EU). The GDPR is based on six principles: lawful basis and transparency,
purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. The
GDPR protects the collecting, processing, and storage of the voters’ data. Using both the NIST and GDPR
as a baseline, BallotOnline will ensure the voters' information will be safe and secure.
Potential Privacy Issue and Mitigation Measures
Stolen data has become a common privacy issue in the past few years. A data breach to
BallotOnline’s CSP resulting in stolen data could cause reputation damage, fines, and criminal
prosecution. If the voters’ information is released, hackers could access their Personally Identifiable
Information (PII), votes could be modified, etc. Since BallotOnline will operate in the EU, they will have
to comply with the GDPR. It is also suggested that BallotOnline also abides by the NIST. The best way to
comply with GDPR is to:
1. Understand the GDPR.
5
2. Identify and document the data BallotOnline has on the voters.
3. Review current data governance practices.
4. Check consent procedures.
5. Assign data protection leads.
6. Establish procedures for reporting breaches.
The best way to comply with the draft with NISTIR 8310 is to:
1. Conduct and oversee voting period activities.
2. Prepare and maintain election systems.
3. Process and maintain voter registration.
4. Prepare for a specific election.
5. Perform ongoing election administration functions.
6. Conduct audits.
7. Conduct elections “wrap-up” activities.
8. Manage crisis/strategic communications.
9. Oversee office administration.
10. Maintain workforce.
Abiding by the GDPR and the NIST will provide checks and balances to keep all the voters’
information safe. It will also prevent fines to BallotOnline because following the GDPR and NIST will
prevent voters' data from being released.
Relevant Security Issues
Every public-facing network with routers, servers, and computers is vulnerable to attacks. When a
company has information a Cyber Threat Actor (CTA) wants, the CTA spends more time focusing on that
target. Typical targets are banks, retail companies, and anywhere the CTA thinks they can make money,
get bragging rights, blackmail, or extort the targeted company. Hackers targeting BallotOnline can make a
political point, sow doubt in the election system, or be an Advanced Persistent Threat (APT) from a
6
foreign government agency. There are many different types of attacks the APT and CTA use. The relevant
security issues to BallotOnline are:
1. Ransomware – The CTA gains access to systems and locks the administrators out until a ransom
is paid to unlock them.
2. APT – A continuous computer hacking process in which a cybercriminal (or CTA) carries out a
prolonged attack against a specific target.
3. Distributed Denial of Service/Denial of Service (DDoS/DoS) – Cyberattack on a server, service,
website, or network which floods Internet traffic to deny legitimate traffic, which would deny
BallotOnline voters a chance to vote.
4. Phishing – A type of social engineering designed for an attacker to send a fraudulent message to
trick a human victim into revealing sensitive information or deploying malicious software like
ransomware on a victim's infrastructure.
5. Data Breaches – A security violation in which sensitive, protected, or confidential data is copied,
transmitted, viewed, stolen, or used by an unauthorized individual.
6. Insider Threat – A cyberattack originating from an individual who works for an organization or
has authorized access to its networks or systems.
BallotOnline’s move to the cloud presents threats not experienced with on-premise data centers. These
risks are:
1. Physical Access – BallotOnline does not have physical access to the servers used by the CSP. The
CSP poses an external insider threat.
2. PII data in a shared Multi-Tenant Environment – Using a public cloud solution puts voters' PII at
risk because a multi-tenant environment is susceptible to a data breach.
3. Stolen Cloud Authentication Credentials – The CSP has limited access to the tenants in the cloud.
Once the CSP is compromised, BallotOnline voter PII could also be compromised.
4. Internet-Accessible Management Application Programming Interface (API) – BallotOnline
administrators do not have physical access to the servers' building, so servers are managed
7
through internet-accessible APIs. API vulnerabilities pose a threat to BallotOnline’s data by
allowing CTA access.
The CSP must offer:
1. Data Security – Encrypt all data at rest, in use, and in transit. Digital certificates and signatures
must be used as much as possible while limiting the use of passwords.
2. Data Access Security – A cloud identity management tool must be used to authenticate each
user’s access to user-specific data. Just-in-time access for administrators to give them access only
for the time necessary to do the task, limiting anyone from having unlimited server rights all the
time.
3. Physical Security – Ensure the CSP has a memorandum of understanding to restrict access to the
servers that BallotOnline is using in the cloud.
4. Application and Infrastructure Security – All APIs, applications, virtual machines, and endpoint
devices must be security-hardened to prevent attacks. All systems must be checked often for
malware, ransomware, and viruses.
5. Network Security – All network devices must use digital certificates and signatures to encrypt the
traffic and access to the device. The CSP must provide DDoS/DoS-resistant internet access and
must be able to provide a firewall with intrusion detection and logging.
Applicable Laws, Regulations, and Frameworks
With BallotOnline expanding worldwide, the laws to protect voter data escalates complexity.
There will be compliance requirements for BallotOnline and the CSP. These regulations can be vague to a
new service like the cloud. Conflicts and differences in regulations can occur between the countries and
jurisdictions BallotOnline plans to service. BallotOnline must abide by the laws in all the nations it
intends to provide services to prevent breaking criminal and civil regulations.
Laws and Regulations
BallotOnline is based in the United States and has mandatory federal and state regulations to
protect voters’ digital PII. The data must comply with the Federal Information Security and Management
8
Act (FISMA), Clarifying Lawful Overseas Use of Data (CLOUD) Act, Electronic Communications
Privacy Act (ECPA), and the Stored Communications Act (SCA). Since BallotOnline is providing a
worldwide solution, the GDPR from the EU must be used to protect the voters in that region. Since the
GDPR has some of the strictest data privacy laws in the world, abiding by the GDPR may protect other
voters that are not in the EU or United States but require their PII to be protected. However, all countries
and jurisdictions might have a law not covered by the GDPR or UNITED STATES law. BallotOnline
must be careful to comply with those also.
Frameworks
Control Objectives for Information and Related Technology (COBIT) is a framework for Data
Protection. This framework was created by Information Systems Audit and Control Association (ISACA)
for IT management and IT governance. This is a framework that BallotOnline can use to protect the
voters’ data. There are many different frameworks to facilitate compliance, protect data, mitigate risks,
and protect the privacy and integrity of the data. This type of framework is built to protect companies like
BallotOnline and customers like BallotOnline voters.
Cyberspace Law and Cloud Service Provider Agreement
Cyberspace law is any law that applies to the internet and internet-related technologies.
Cyberspace law is one of the newest legal systems and is growing as the world relies more on the internet
for day-to-day business. BallotOnline will need to focus on cyberspace law to understand how this applies
to the country, county, or jurisdiction and resolve conflicts and disputes. BallotOnline will need to
dedicate a team to focus on cyberspace law for every region they operate. This team should build the
Cloud Service Provider Agreement (CSPA).
The CSPA provides documents that give a defined statement of work, description of services,
performance requirements, service level agreement, disaster recovery, acceptable use policy, criteria, and
customer agreement. The CSPA will clearly define the roles and responsibilities of the CSP and
BallotOnline before the transition to the cloud. The CSPA will determine the liabilities the CSP and
BallotOnline agree to in the CSPA. It also lists the breach of contract, dispute resolution process, and
9
penalties. The CSPA will be used to decide security cooperation. CSPA is where the Cloud Service
Partner, Cloud Service Provider, and Cloud Service Customer (BallotOnline) explain where all three are
required to share the responsibility to secure BallotOnline data. The CSPA is a binding contract between
the vendor and the customer.
Compliance Requirements
BallotOnline is required to meet compliance requirements to operate as an online voting solution.
The compliance requirements are complex but designed to protect the consumer and the company. Cloud
solution compliance is divided into these requirements:
1. Geographic compliance
2. Election industry compliance
3. Data compliance
Geographic Compliance
10
Since BallotOnline will be operating in many regions of the world, the two major regions are the
United States and EU; BallotOnline will have to comply with all the laws in the regions they serve.
Geographic compliance includes individual state compliance like California and Florida. Also, some
countries in the EU have strong electoral rights.
Election Industry Compliance
The Federal Election Campaign Act of 1971, the Help America Vote Act of 2002, the National
Voter Registration Act (NVRA) of 1993, and the Military and Overseas Voting Empowerment (MOVE)
Act of 2009 are laws BallotOnline must comply with to give the voters access to vote. The state-by-state
voting law is based on showing proof that each person is a registered voter. BallotOnline system must
take that into account.
The EU is a group of countries. Unlike the United States, there is no one law to guide them all.
BallotOnline will have to comply with the laws of all 27 countries that are in the EU. Compliance with all
the countries in the EU will be a complex task for BallotOnline.
Data Compliance
The United States does not have a single principal data protection legislation. They have many
laws that can apply to this situation. One of those laws is the Federal Trade Commission Act which
empowers the Federal Trade Commission (FTC) to comply with published privacy promises. Many other
federal-level laws apply to a consumer PII but do not apply directly to voter information. Only states acts
like the California Privacy Rights Act (CPRA) and Virginia Consumer Data Protection Act (CDPA) have
laws for data compliance but none as broad as the GDPR.
The EU’s GDPR will be a requirement for BallotOnline due to operating in this region. The
GDPR is the strictest in the world. Any violations of the articles of this law could lead to civil or criminal
penalties.
In general terms, BallotOnline must protect all data at rest, in use, and in transit. The data must be
easily moved securely between different IT environments. The information in the data must be classified
to limit who can or should be able to access the data.
11
Proposal for a Compliance Program
BallotOnline must develop and implement a compliance program to reduce the risk of legal fines
and damages to the company from violations. This compliance program will ensure BallotOnline will
protect the voters’ data, comply with the privacy and data laws, and protect from being fined.
The components of the compliance program are below:
Monitor compliance with policy, standards, and security controls
Automate technical control monitoring and reporting for compliance with geographic, election,
and data requirements. Automating this process simplifies the collection for future auditing.
Implement manual monitoring of non-technical controls. The CSP will provide logs of who
physically enters the section of the data center where BallotOnline is managing servers.
Security Information and Event Management (SIEM) software tool will be used for continuous
auditing and monitoring
All compliance monitoring will be linked with the SIEM.
12
A compliance manager tool will be used to assess all the risks.
The employees that have oversight of compliance are the Chief Information Security Officer
(CISO), Security Manager (SM), Security Engineer (SE), and Security Analyst (SA).
The CISO is the leader of the Cloud Security Team. The CISO plans the programs, strategies,
policies, and procedures to protect BallotOnline’s cloud data.
The SM oversees the security team. SM builds the process, develops the security technology
stack, and provides technical guidance and managerial oversight.
The SE team focuses on SIEM, security of endpoints, vulnerability assessment, internal and
external penetration testing, threat intelligence, and all other areas of security engineering for
BallotOnline.
The SA team detects, investigates, and responds to security incidents. The SA is also known as an
incident responder. The SA team will be on call 24 hours a day, 7 days a week and 365 days a
year.
The policy framework COBIT Design & Implementation and Implementing the NIST
Cybersecurity Framework Using COBIT 2019 will be used to manage the compliance program.
The GDPR, FISMA, CLOUD, ECPA, and SCA are laws the COBIT 2019 will be built around to
ensure compliance with the regulations.
A Service Level Agreement with the CSP will be used to enforce the COBIT 2019 policy.
Continuous Self-Assessment
The SE will automate endpoint security, vulnerability assessment, internal penetration tests, and
threat intelligence.
The SM and SE will conduct periodic self-assessments security tests.
The CISO, SM, SE, and SA will be trained and certified in COBIT 2019, GDPR, FISMA,
CLOUD, ECPA, and SCA.
Respond to events and changes to risk
The CISO and SM will integrate security procedures with the compliance program for response
13
management.
The CISO will create a policy to respond to unintentional changes in controls due to new security
threats.
The SA team will handle security incidents. The SA team will log all actions in the Information
Technology Service Management (ITSM) software team so the compliance team can be informed
and look for other similar security incidents.
The CISO will make the corrective action plan with the SM. The remedial plan will be based on
local data storage and privacy laws.
Communicate events and changes to risk
Create a reporting tree and thresholds for each type of security incident.
Include the legal team in reporting security report chain.
Make sure appropriate regulatory organizations are notified when required.
An ITSM software tool like BMC Remedy should be used to automate the workflow for the
compliance process and all other change management for BallotOnline.
The ITSM software tool will provide collaboration between all managers and the compliance
team. The ITSM makes it possible for a security event to be tracked from the security issue until
the issue is resolved.