NIST framework focuses on election cybersecurity

The new draft framework combining election security and cybersecurity is the first of its kind for NIST.

voting scrutiny (Bakhtiar Zein/Shutterstock.com)
 

The National Institute of Standards and Technology on Monday published a draft framework to help local election officials prepare for and respond to cyber threats.

The framework takes NIST's pre-existing cybersecurity best practices and applies them to election infrastructure such as polling places, voter registration databases and voting machines.

"The guide can help these officials reduce the risk of disruptions to the major tasks they must perform in the process of an election," according to NIST. "These range from the immediate concerns of an election day, such as vote processing or communicating the details of a problem or crisis, to longer-term efforts, like maintaining election and voter registration systems."

The new draft framework is the first time NIST has combined election security and cybersecurity in one of its playbooks, according to one of the authors.

Since the end of the 2020 elections, officials from the Cybersecurity and Infrastructure Security Agency, which helped NIST created the draft framework, have stressed the large number of assistance requests they received from local and state election officials.

A declassified assessment of the 2020 elections by the intelligence community concluded that foreign adversaries for the most part did not attempt to meddle by hacking, but rather through influence campaigns.

However the IC did acknowledge there were some number of successful "compromises" of state and local government networks prior to election day as well as many more unsuccessful attempts.

NIST will accept comments on the draft through May 14.