Abstract

There are many security challenges associated with the use of Internet voting solutions. While the paper does not advocate for the use of Internet voting, it asserts that if an Internet voting solution is going to be used, its deployment must be undertaken with continuous security auditing in place — auditing that begins with development of the system by the manufacturer or election jurisdiction and continues throughout the system's use in the field.

The paper demonstrates how real-time election forensics and other security methodologies already used successfully with electronic voting systems can be applied to mitigate risk and detect issues in Internet-based voting solutions. It works through the product development process — determining what to develop, and how — and argues for a requirements development methodology such as CMMI at Maturity Level 3, coupled with sustained surveillance for emergent threats.