* *
* * *
* * *
*
*
* * *
*

Case Studies - Security

Quality Assurance of the E-Voting Pilots for the ODPM

This Case Study details work performed by QinetiQ in the run-up to the May 2003 Local Government elections.

*

In support of the Office of the Deputy Prime Minister (ODPM), QinetiQ was entrusted with the evaluation of 9 of the 18 e-voting pilots in the May 2003 local government elections. This clearly demonstrated the ODPM's confidence in our experience, expertise and impartiality.

The evaluation focused on four main areas

  • Security
  • Technology
  • Configuration Management
  • Project Management

*

The primary objectives were to establish confidence that the systems supporting the pilots would be robust when put to use, and that elections depending on them would meet the required standards of security.

QinetiQ carried out extensive penetration testing at both the hosting and infrastructure sites and the local council channel suppliers. This was followed by a technology review of system architectures and an audit of the project and configuration management procedures utilised by the suppliers.

*

In each phase, the focus was to identify how the ODPM could mitigate any additional risks inherent to the pilot programme through the use of the updated risk assessment and Quality
Assurance methodologies. The dovetailing of QinetiQ's work programme into the busy schedules of over 20 separate but interworking suppliers was a serious challenge.

To achieve this, QinetiQ adopted a phased approach to the assignment, which combined flexibility with the rigour of
industry-standard techniques and QinetiQ's own extensive experience.The results of these activities provided ODPM managers and the Local Government Minister with an appropriate
level of assurance that the suppliers had identified a suitable set of baseline security measures.
Furthermore, the results proved that the existing information security measures were valid and that additional risks inherent in the pilot programme were highlighted and could be suitably
managed.

*

Throughout the assurance programme, QinetiQ was able to provide real-time advice to suppliers and the ODPM to ensure the required levels of security were met and to identify risks as they became evident. The assurance programme encompassed supplier obligations before, during and after the elections, and has resulted in a number of recommendations to generate a best practice solution for future e-voting pilots.

QinetiQ's track record makes it the partner of choice for many, but equally important is QinetiQ's ability to meet the challenges a changing world brings. In summary, as technologies and communication systems advance, so must the strategies to protect
them. These strategies must focus not just on the technology, but also on the supporting processes and people.

*
Related sections
Supporting information
*
* * *
*
*
*   *