Risk and compliances2

profiledoddy77
CH_Project2_Final_Risk_Assessment_and_Compliance_Report.docx13.pdf

1

Final Risk Assessment and Compliance Report

Name

University of Maryland Global Campus

CCA 610: Cloud Services and Technologies

Professor Richard Utter

November 23, 2021

2

Executive Summary

Cloud computing is an alternative way for BallotOnline to save cost by moving the on-premises

data center to the cloud. However, there are some risks with moving to the cloud. The Final Risk

Assessment and Compliance Report explains the threats and how BallotOnline needs to comply with

geographic laws, election laws, data protection laws, and policies. This assessment is written for the

executives of BallotOnline. The Final Risk Assessment and Compliance Report is a careful evaluation

that details all the possible risks by analyzing and using a risk matrix to explain how the risk can be

avoided, mitigated, or accepted. Out of the top ten items listed as risks, most were unlikely to happen; and

the risk that was likely to occur had tangible ways to mitigate, avoid or transfer the risk. Most risks for the

cloud data center are the same as using an on-premises data center.

The risk management guidelines list standards that BallotOnline must comply with to ensure the

customers' data is safe. The standards or laws that will be used are the National Institute of Standards and

Technology, General Data Protection Regulation, and Cybersecurity Framework Election Infrastructure

Profile 8310. The General Data Protection Regulation is a European Union law, but it can be used to

protect all BallotOnline voters worldwide. This assessment covers the importance of protecting the voters’

data to prevent legal actions or fines due to potential privacy issues. There are relevant security issues that

apply to both on-premises and cloud-based datacenter. Both the security issues and the mitigation

methods are discussed in this assessment. Since BallotOnline will provide voting access to voters

worldwide, BallotOnline must comply with local laws and regulations to protect the company from fines

and penalties. The geographic, election industry, and data compliance requirements are discussed and

reviewed. This assessment lists action plans and proposes a compliance program proposal to prevent

violating any laws or regulations. After meticulously evaluating all the risks; a governance, risk, and

compliance roadmap is suggested as the official policy to mitigate all the risks with moving BallotOnline

to the cloud.

3

Risk Analysis

BallotOnline is taking some risks by moving to the cloud. The risks of moving data to the cloud

are similar to those of having an on-premises data center. However, the benefits outweigh the potential

risks. BallotOnline must work with the Cloud Service Provider (CSP) and within the regulations of the

local country to mitigate those risks.

Risks can be listed in two main areas: external risks and internal risks. An external risk could

come from a threat outside of the company. Examples of external risks are hackers trying to steal or

destroy voter data, an internet outage, a power outage, a fire, or a flood. An internal risk could come from

inside the company. Examples of internal risks are insider threat hackers, untrained programmers, or data

loss. These are the same threats that could affect BallotOnline while using an on-premise data center.

BallotOnline can face the same risks at a lesser cost and have greater reach using a CSP. Table 1 has the

risk matrix based on the significant threats to BallotOnline.

Risk Threat Result Risk Detail Odds Impact Risk Score Response Action Type

Response Actions

Fire Accidental or environmental

Equipment damaged and an outage

No fire suppression system or system cannot stop the fire

Unlikel y

Major Unacceptable Risk: Extremely High

Mitigate Disaster recovery/failover

Loss of power

Accidental or environmental

Outage Lack of access to voter information

Unlikel y

Major Unacceptable Risk: Extremely High

Mitigate Disaster recovery/failover

Programming error

Training Software or routing stop working

Voting software does not work or is not accessible

Likely Major Unacceptable Risk: Extremely High

Mitigate This will be mitigated with training and testing

Passwords released

Adversarial outsider (e.g., hacker)

An unauthorized person gains access to BallotOnline

An unauthorized person can steal data or BallotOnline voting software

Unlikel y

Major Unacceptable Risk: Extremely High

Avoid All logins will be with PKI certs. No passwords are allowed.

Denial of Service

Adversarial outsider (e.g., hacker)

Outage Voters will not be able to vote. Admin will not be able to access the system

Unlikel y

Moderate Acceptable Risk: Medium

Transfer Failover

Worldwide internet outage

Accidental or environmental

Outage Voters will not be able to vote. Admin will not be able to access the system

Unlikel y

Minor Acceptable Risk: Low

Accept Wait for the internet to recover

Internet outage at Cloud Provider

Accidental or environmental

Outage Voters will not be able to vote. Admin will not be able to access the system

Unlikel y

Minor Acceptable Risk: Low

Transfer Disaster recovery/failover. Also requiring the Cloud Provider to have different ISPs.

Data Breach Adversarial outsider (e.g., hacker)

Stolen data with PII released to the public

Report breach to GDPR and voters

Likely Major Unacceptable Risk: Extremely High

Mitigate Encrypt all data with strong encryption and PKI

Data Loss Technological failure

Voter data lost No backups of the data Unlikel y

Moderate Acceptable Risk: Low

Avoid Backup all files securely in three locations

Custom Software too complex

Training Admin slow to move to the cloud

The admins do not have a complete understanding of how to move to the cloud

Very Likely

Major Unacceptable Risk: Extremely High

Mitigate Training

Table 1

The most important thing for BallotOnline is to protect the voters’ data from internal and external

risks. The data must remain unaltered to ensure it is correct and must be encrypted. If BallotOnline lost

the voters’ data, they would have to pay fines, and voters would lose confidence in their system.

4

Risk Management Guidelines

For BallotOnline to abide by local laws and cybersecurity governance, it must use cybersecurity

standards to reduce the risks for the voters. BallotOnline should consider at least two cybersecurity

standards as the baseline. The first standard for BallotOnline is the National Institute of Standards and

Technology (NIST) Cybersecurity Framework. The second baseline for security is General Data

Protection Regulation (GDPR).

NIST was one of the original contributors to the United States cybersecurity industry standards

for the cloud and made guidelines for protecting the use of computers for voting. NIST has an adaptive,

risk-based framework that works in every step of an election cycle: the pre-election, election day, and

post-election activities. NIST calls this the Cybersecurity Framework Election Infrastructure Profile

(NISTIR) 8310. The NISTIR 8310 draws upon the experience of election participants and cybersecurity

professionals worldwide to offer a way to secure all elements of election technology.

The GDPR has some of the strictest online security and privacy law in the world. Since

BallotOnline is worldwide, using GDPR as a baseline for cloud election security would abide by the laws

in the European Union (EU). The GDPR is based on six principles: lawful basis and transparency,

purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. The

GDPR protects the collecting, processing, and storage of the voters’ data. Using both the NIST and GDPR

as a baseline, BallotOnline will ensure the voters' information will be safe and secure.

Potential Privacy Issue and Mitigation Measures

Stolen data has become a common privacy issue in the past few years. A data breach to

BallotOnline’s CSP resulting in stolen data could cause reputation damage, fines, and criminal

prosecution. If the voters’ information is released, hackers could access their Personally Identifiable

Information (PII), votes could be modified, etc. Since BallotOnline will operate in the EU, they will have

to comply with the GDPR. It is also suggested that BallotOnline also abides by the NIST. The best way to

comply with GDPR is to:

1. Understand the GDPR.

5

2. Identify and document the data BallotOnline has on the voters.

3. Review current data governance practices.

4. Check consent procedures.

5. Assign data protection leads.

6. Establish procedures for reporting breaches.

The best way to comply with the draft with NISTIR 8310 is to:

1. Conduct and oversee voting period activities.

2. Prepare and maintain election systems.

3. Process and maintain voter registration.

4. Prepare for a specific election.

5. Perform ongoing election administration functions.

6. Conduct audits.

7. Conduct elections “wrap-up” activities.

8. Manage crisis/strategic communications.

9. Oversee office administration.

10. Maintain workforce.

Abiding by the GDPR and the NIST will provide checks and balances to keep all the voters’

information safe. It will also prevent fines to BallotOnline because following the GDPR and NIST will

prevent voters' data from being released.

Relevant Security Issues

Every public-facing network with routers, servers, and computers is vulnerable to attacks. When a

company has information a Cyber Threat Actor (CTA) wants, the CTA spends more time focusing on that

target. Typical targets are banks, retail companies, and anywhere the CTA thinks they can make money,

get bragging rights, blackmail, or extort the targeted company. Hackers targeting BallotOnline can make a

political point, sow doubt in the election system, or be an Advanced Persistent Threat (APT) from a

6

foreign government agency. There are many different types of attacks the APT and CTA use. The relevant

security issues to BallotOnline are:

1. Ransomware – The CTA gains access to systems and locks the administrators out until a ransom

is paid to unlock them.

2. APT – A continuous computer hacking process in which a cybercriminal (or CTA) carries out a

prolonged attack against a specific target.

3. Distributed Denial of Service/Denial of Service (DDoS/DoS) – Cyberattack on a server, service,

website, or network which floods Internet traffic to deny legitimate traffic, which would deny

BallotOnline voters a chance to vote.

4. Phishing – A type of social engineering designed for an attacker to send a fraudulent message to

trick a human victim into revealing sensitive information or deploying malicious software like

ransomware on a victim's infrastructure.

5. Data Breaches – A security violation in which sensitive, protected, or confidential data is copied,

transmitted, viewed, stolen, or used by an unauthorized individual.

6. Insider Threat – A cyberattack originating from an individual who works for an organization or

has authorized access to its networks or systems.

BallotOnline’s move to the cloud presents threats not experienced with on-premise data centers. These

risks are:

1. Physical Access – BallotOnline does not have physical access to the servers used by the CSP. The

CSP poses an external insider threat.

2. PII data in a shared Multi-Tenant Environment – Using a public cloud solution puts voters' PII at

risk because a multi-tenant environment is susceptible to a data breach.

3. Stolen Cloud Authentication Credentials – The CSP has limited access to the tenants in the cloud.

Once the CSP is compromised, BallotOnline voter PII could also be compromised.

4. Internet-Accessible Management Application Programming Interface (API) – BallotOnline

administrators do not have physical access to the servers' building, so servers are managed

7

through internet-accessible APIs. API vulnerabilities pose a threat to BallotOnline’s data by

allowing CTA access.

The CSP must offer:

1. Data Security – Encrypt all data at rest, in use, and in transit. Digital certificates and signatures

must be used as much as possible while limiting the use of passwords.

2. Data Access Security – A cloud identity management tool must be used to authenticate each

user’s access to user-specific data. Just-in-time access for administrators to give them access only

for the time necessary to do the task, limiting anyone from having unlimited server rights all the

time.

3. Physical Security – Ensure the CSP has a memorandum of understanding to restrict access to the

servers that BallotOnline is using in the cloud.

4. Application and Infrastructure Security – All APIs, applications, virtual machines, and endpoint

devices must be security-hardened to prevent attacks. All systems must be checked often for

malware, ransomware, and viruses.

5. Network Security – All network devices must use digital certificates and signatures to encrypt the

traffic and access to the device. The CSP must provide DDoS/DoS-resistant internet access and

must be able to provide a firewall with intrusion detection and logging.

Applicable Laws, Regulations, and Frameworks

With BallotOnline expanding worldwide, the laws to protect voter data escalates complexity.

There will be compliance requirements for BallotOnline and the CSP. These regulations can be vague to a

new service like the cloud. Conflicts and differences in regulations can occur between the countries and

jurisdictions BallotOnline plans to service. BallotOnline must abide by the laws in all the nations it

intends to provide services to prevent breaking criminal and civil regulations.

Laws and Regulations

BallotOnline is based in the United States and has mandatory federal and state regulations to

protect voters’ digital PII. The data must comply with the Federal Information Security and Management

8

Act (FISMA), Clarifying Lawful Overseas Use of Data (CLOUD) Act, Electronic Communications

Privacy Act (ECPA), and the Stored Communications Act (SCA). Since BallotOnline is providing a

worldwide solution, the GDPR from the EU must be used to protect the voters in that region. Since the

GDPR has some of the strictest data privacy laws in the world, abiding by the GDPR may protect other

voters that are not in the EU or United States but require their PII to be protected. However, all countries

and jurisdictions might have a law not covered by the GDPR or UNITED STATES law. BallotOnline

must be careful to comply with those also.

Frameworks

Control Objectives for Information and Related Technology (COBIT) is a framework for Data

Protection. This framework was created by Information Systems Audit and Control Association (ISACA)

for IT management and IT governance. This is a framework that BallotOnline can use to protect the

voters’ data. There are many different frameworks to facilitate compliance, protect data, mitigate risks,

and protect the privacy and integrity of the data. This type of framework is built to protect companies like

BallotOnline and customers like BallotOnline voters.

Cyberspace Law and Cloud Service Provider Agreement

Cyberspace law is any law that applies to the internet and internet-related technologies.

Cyberspace law is one of the newest legal systems and is growing as the world relies more on the internet

for day-to-day business. BallotOnline will need to focus on cyberspace law to understand how this applies

to the country, county, or jurisdiction and resolve conflicts and disputes. BallotOnline will need to

dedicate a team to focus on cyberspace law for every region they operate. This team should build the

Cloud Service Provider Agreement (CSPA).

The CSPA provides documents that give a defined statement of work, description of services,

performance requirements, service level agreement, disaster recovery, acceptable use policy, criteria, and

customer agreement. The CSPA will clearly define the roles and responsibilities of the CSP and

BallotOnline before the transition to the cloud. The CSPA will determine the liabilities the CSP and

BallotOnline agree to in the CSPA. It also lists the breach of contract, dispute resolution process, and

9

penalties. The CSPA will be used to decide security cooperation. CSPA is where the Cloud Service

Partner, Cloud Service Provider, and Cloud Service Customer (BallotOnline) explain where all three are

required to share the responsibility to secure BallotOnline data. The CSPA is a binding contract between

the vendor and the customer.

Compliance Requirements

BallotOnline is required to meet compliance requirements to operate as an online voting solution.

The compliance requirements are complex but designed to protect the consumer and the company. Cloud

solution compliance is divided into these requirements:

1. Geographic compliance

2. Election industry compliance

3. Data compliance

Geographic Compliance

10

Since BallotOnline will be operating in many regions of the world, the two major regions are the

United States and EU; BallotOnline will have to comply with all the laws in the regions they serve.

Geographic compliance includes individual state compliance like California and Florida. Also, some

countries in the EU have strong electoral rights.

Election Industry Compliance

The Federal Election Campaign Act of 1971, the Help America Vote Act of 2002, the National

Voter Registration Act (NVRA) of 1993, and the Military and Overseas Voting Empowerment (MOVE)

Act of 2009 are laws BallotOnline must comply with to give the voters access to vote. The state-by-state

voting law is based on showing proof that each person is a registered voter. BallotOnline system must

take that into account.

The EU is a group of countries. Unlike the United States, there is no one law to guide them all.

BallotOnline will have to comply with the laws of all 27 countries that are in the EU. Compliance with all

the countries in the EU will be a complex task for BallotOnline.

Data Compliance

The United States does not have a single principal data protection legislation. They have many

laws that can apply to this situation. One of those laws is the Federal Trade Commission Act which

empowers the Federal Trade Commission (FTC) to comply with published privacy promises. Many other

federal-level laws apply to a consumer PII but do not apply directly to voter information. Only states acts

like the California Privacy Rights Act (CPRA) and Virginia Consumer Data Protection Act (CDPA) have

laws for data compliance but none as broad as the GDPR.

The EU’s GDPR will be a requirement for BallotOnline due to operating in this region. The

GDPR is the strictest in the world. Any violations of the articles of this law could lead to civil or criminal

penalties.

In general terms, BallotOnline must protect all data at rest, in use, and in transit. The data must be

easily moved securely between different IT environments. The information in the data must be classified

to limit who can or should be able to access the data.

11

Proposal for a Compliance Program

BallotOnline must develop and implement a compliance program to reduce the risk of legal fines

and damages to the company from violations. This compliance program will ensure BallotOnline will

protect the voters’ data, comply with the privacy and data laws, and protect from being fined.

The components of the compliance program are below:

Monitor compliance with policy, standards, and security controls

 Automate technical control monitoring and reporting for compliance with geographic, election,

and data requirements. Automating this process simplifies the collection for future auditing.

 Implement manual monitoring of non-technical controls. The CSP will provide logs of who

physically enters the section of the data center where BallotOnline is managing servers.

 Security Information and Event Management (SIEM) software tool will be used for continuous

auditing and monitoring

 All compliance monitoring will be linked with the SIEM.

12

 A compliance manager tool will be used to assess all the risks.

 The employees that have oversight of compliance are the Chief Information Security Officer

(CISO), Security Manager (SM), Security Engineer (SE), and Security Analyst (SA).

 The CISO is the leader of the Cloud Security Team. The CISO plans the programs, strategies,

policies, and procedures to protect BallotOnline’s cloud data.

 The SM oversees the security team. SM builds the process, develops the security technology

stack, and provides technical guidance and managerial oversight.

 The SE team focuses on SIEM, security of endpoints, vulnerability assessment, internal and

external penetration testing, threat intelligence, and all other areas of security engineering for

BallotOnline.

 The SA team detects, investigates, and responds to security incidents. The SA is also known as an

incident responder. The SA team will be on call 24 hours a day, 7 days a week and 365 days a

year.

 The policy framework COBIT Design & Implementation and Implementing the NIST

Cybersecurity Framework Using COBIT 2019 will be used to manage the compliance program.

 The GDPR, FISMA, CLOUD, ECPA, and SCA are laws the COBIT 2019 will be built around to

ensure compliance with the regulations.

 A Service Level Agreement with the CSP will be used to enforce the COBIT 2019 policy.

Continuous Self-Assessment

 The SE will automate endpoint security, vulnerability assessment, internal penetration tests, and

threat intelligence.

 The SM and SE will conduct periodic self-assessments security tests.

 The CISO, SM, SE, and SA will be trained and certified in COBIT 2019, GDPR, FISMA,

CLOUD, ECPA, and SCA.

Respond to events and changes to risk

 The CISO and SM will integrate security procedures with the compliance program for response

13

management.

 The CISO will create a policy to respond to unintentional changes in controls due to new security

threats.

 The SA team will handle security incidents. The SA team will log all actions in the Information

Technology Service Management (ITSM) software team so the compliance team can be informed

and look for other similar security incidents.

 The CISO will make the corrective action plan with the SM. The remedial plan will be based on

local data storage and privacy laws.

Communicate events and changes to risk

 Create a reporting tree and thresholds for each type of security incident.

 Include the legal team in reporting security report chain.

 Make sure appropriate regulatory organizations are notified when required.

 An ITSM software tool like BMC Remedy should be used to automate the workflow for the

compliance process and all other change management for BallotOnline.

 The ITSM software tool will provide collaboration between all managers and the compliance

team. The ITSM makes it possible for a security event to be tracked from the security issue until

the issue is resolved.