书签 分享 收藏 举报 版权申诉 / 22
上传文档赚钱

类型Beyond-the-Ballot-Box-Securing-Americas-Supporting-Election-Technology.pptx

  • 上传人(卖家):无敌的果实
  • 文档编号:2519596
  • 上传时间:2022-04-28
  • 格式:PPTX
  • 页数:22
  • 大小:1.41MB
  • 【下载声明】
    1. 本站全部试题类文档,若标题没写含答案,则无答案;标题注明含答案的文档,主观题也可能无答案。请谨慎下单,一旦售出,不予退换。
    2. 本站全部PPT文档均不含视频和音频,PPT中出现的音频或视频标识(或文字)仅表示流程,实际无音频或视频文件。请谨慎下单,一旦售出,不予退换。
    3. 本页资料《Beyond-the-Ballot-Box-Securing-Americas-Supporting-Election-Technology.pptx》由用户(无敌的果实)主动上传,其收益全归该用户。163文库仅提供信息存储空间,仅对该用户上传内容的表现方式做保护处理,对上传内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知163文库(点击联系客服),我们立即给予删除!
    4. 请根据预览情况,自愿下载本文。本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
    5. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007及以上版本和PDF阅读器,压缩文件请下载最新的WinRAR软件解压。
    配套讲稿:

    如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。

    特殊限制:

    部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。

    关 键  词:
    Beyond the Ballot Box Securing Americas Supporting Election Technology
    资源描述:

    1、-Beyond the Ballot Box: SecuringAmericas Supporting ElectionTechnology#RSACHow to secureinternet-connectedelection services160 best practicestailored for electiontechnologyTarget audience istechnology providersDeveloped with thehelp of electionofficials andtechnology providersNon-Voting Election Tec

    2、hnology Best PracticesExposure to morethreatsVote CaptureVote TabulationSignificant impact onvoter confidenceElection Management SystemVery few existingstandardsElectronic Ballot DeliveryE-PollbooksVoter Registration SystemElection Night ReportingInternet ExposureOrganization and StructureTechnology

    3、 AreasProfile Levels321StructureTechnology AreasBest PracticesDescriptionBackgroundThreatsRecommendationsDescriptionElection TechnologyApplicationGovernanceElection NotesDenial of Service Example1.1.3 Deny Communications with Known Malicious IP Addresses1.3.4 Install the Latest Stable Version of Any

    4、 Security-Related Updates on All Network Devices1.5.1 Establish and Maintain Effective Partnerships With Your Upstream Network Service Provider1.5.2 Port and Packet Size Filtering11.5.7 Set Up Out-of-Band Communication for DDoS Response1.5.3 Enable Firewall Logging231.5.5 Configure Devices to Detect

    5、 and Alarm on Traffic Anomalies5.4.2 Assign Job Titles and Duties for Incident Response1.5.4 Configure Perimeter Devices to Prevent Common Types of Attacks1.5.6 Establish DDoS Mitigation Services With a Third-Party DDoS Mitigation Provider3.2.12 Deploy Web Application FirewallsRansomware Example1.4.

    6、5 Ensure All Backups Have at Least One OfflineBackup Destination1.1.4 Deny Communications with KnownMalicious IP Addresses2.3.1 Utilize Centrally Managed Anti-MalwareSoftware1.1.6 Deploy Network-Based IDS Sensors1.4.1 Ensure Regular Automated Backups1.4.2 Perform Complete System Backups1.4.4 Protect

    7、 Backups14.1.1 Maintain an Inventory of Sensitive Information4.1.2 Remove Sensitive Data or Systems Not RegularlyAccessed by the Organization1.4.3 Verify Data on Backup MediaAnti-Exploit Technologies231.1.7 Deploy Network-Based IntrusionPrevention Systems2.4.3 Ensure the Use of Dedicated Administrat

    8、iveAccounts2.3.3 Enable Operating System Anti-Exploitation Features and Deploy4.2.5 Segment the Network Based on Sensitivity1.1.2 Scan for Unauthorized Connectionsacross Trusted Network Boundaries2.3.7 Deploy a Host-Based Intrusion Detection System4.1.4 Monitor and Detect Any Unauthorized Use ofEncr

    9、yption1.4.6 Verify Complete System RecoveryUnauthorized Data Modification Example1.6.7 Leverage the Advanced EncryptionStandard (AES) to Encrypt Wireless Data3.1.2 Use the Latest Best Practices for Identifying andAuthenticating Users2.2.1 Run Automated Vulnerability ScanningTools3.1.3 Use Best Pract

    10、ices for Securely Handling Inputand Output12.2.5 Deploy Automated Software PatchManagement Tools3.1.4 Deploy Appropriate Access Control Mechanisms4.2.2 Digitally Sign Sensitive Information in Transit2.4.2 Change Default Passwords4.3.1 Follow Secure Configuration Guidance for CloudStorage3.1.1 Store

    11、and Communicate Data Securely1.4.3 Verify Data on Backup Media3.2.16 Use Standard Hardening ConfigurationTemplates for Databases232.2.2 Perform Authenticated VulnerabilityScanning5.1.3 Require Multi-Factor Authentication2.5.4 Use Write-Once or Formatted Media1.1.9 Deploy Application Layer FilteringP

    12、roxy Serverinto Sensitive Systems3.2.14 Deploy Web Application Firewalls (WAFs)1.4.6 Verify Complete System Recovery4.2.9 Enforce Access Control to Data throughAutomated Tools2.5.8 Use USB Write Blocker to Transfer DataVerifying Election Technology withRABET-VRABET-V: Rapid Architecture-Based Electi

    13、on TechnologyVerification#RSACWhat is RABET-VRABET-V is an election technology verification process thatsupports rapid product changes by designInformed by our community of election stakeholdersUses a risk-based approach to verifying product revisions, wherethe risk estimate is based heavily on the

    14、product architectureand the providers software development processes.Leverages modern software development, testing, anddeployment processesRABET-V Process FlowRABET-V is a total of seven activities,five of which are conditional activitiesRepeated for initial review andsubsequent product revisionsTh

    15、e extent to which activities areused for each revision is basedon the scenario and the risk associatedwith the product changesRABET-V Initial ReviewUnique product Testing Rules aredetermined based on riskThe Architecture Review, ProcessAssessment, and Security ClaimsValidation activities provide ass

    16、ertionsabout the systems construction whichinform the Testing RulesDeterminationTesting Rules determine how to testproduct changesProcess AssessmentFocuses on developers softwaredevelopment lifecycle processesProduct changes resulting fromorganizations with more matureprocesses will be considered lo

    17、werriskMore reliable process artifacts makeRABET-V testing more streamlinedArchitecture ReviewResults in assertions about how thesystem should be tested System Software Security DataWell-architected solutions will resultin the maximum amount ofassertions and shorter verificationcyclesSecurity Claims

    18、 ValidationLooks at the claims made about theproduct securityValidates claims and keyarchitectural elements supportingthe claimsValidated claims are published at theend of each iterationTesting Rules DeterminationBuilds a set of Testing Rules toachieve the most rapid, flexible, andreliable testing o

    19、f product revisionspossible given the productarchitecture and providersprocessesMatches test methods with changetypesProduct Verification and ReportingTest Plan created from Testing RulesTest Plan is more streamlined forsmall, low-risk change setsWill leverage product developmentartifacts when possi

    20、bleReporting on product goals,expected usage, validated securityclaims, and verified product changesRABET-V ProvidesRapid testing of many product revisions, allowing products to innovate andmaintain proper security patchesRe-verification of product changes at a minimum costIncentives for high-qualit

    21、y, modern system architectures that are more resistant toattacks and more resilient in recoveryIncentives for technology providers to have robust, risk-mitigating softwaredevelopment processesIncentives to update in smaller, more manageable cycles, more accuratelyreflecting the modern age of softwar

    22、e developmentA consistent basis from which approval authorities (namely states) can drawinformation, resulting in quicker decisions and reduced, amortized overall cost.RABET-V Pilot ProgramLaunched in February 2020 Steering Committee Federal agencies, states election officials, vendors Technical Adv

    23、isory Committee industry expertsDeveloping our Working ModelGet the latest information on our project hub: https:/ Pilot Program QuestionsWhat are the time and cost expectations for each activity duringthe initial and subsequent iterations?What is the best way to conduct architecture reviews and are

    24、they are risk-informing as we propose?What is the best way to conduct process assessments and arethey as risk-information as we propose?What is the best approach to a long term RABET-V process?Apply What Youve Learned TodayNext week you should: Learn and adopt the security best practices for non-vot

    25、ing election technology Begin to follow the RABET-V pilot at https:/ the first three months following this presentation you should: Understand how to secure your election technology and begin implementingmissing controlsWithin six months you should: Review the RABET-V pilot program reports Prepare your product for RABET-V21Thank You#RSAC

    展开阅读全文
    提示  163文库所有资源均是用户自行上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作他用。
    关于本文
    本文标题:Beyond-the-Ballot-Box-Securing-Americas-Supporting-Election-Technology.pptx
    链接地址:https://www.163wenku.com/p-2519596.html

    Copyright@ 2017-2037 Www.163WenKu.Com  网站版权所有  |  资源地图   
    IPC备案号:蜀ICP备2021032737号  | 川公网安备 51099002000191号


    侵权投诉QQ:3464097650  资料上传QQ:3464097650
       


    【声明】本站为“文档C2C交易模式”,即用户上传的文档直接卖给(下载)用户,本站只是网络空间服务平台,本站所有原创文档下载所得归上传人所有,如您发现上传作品侵犯了您的版权,请立刻联系我们并提供证据,我们将在3个工作日内予以改正。

    163文库