Join our Newsletter — 33% off our NHI Course

Election Integrity

Election integrity is the condition in which voting, counting, and result reporting remain trustworthy, accurate, and resistant to manipulation. It depends on strong identity assurance, reliable ballot issuance, auditable processes, and controls that prevent impersonation, fraudulent voting, and unauthorized changes to the outcome.

How Election Integrity Is Maintained

Election integrity is not a single control, but a chain of controls that has to work from voter registration through ballot issuance, tallying, and publication. The core design goal is simple: each legitimate vote should be recorded once, counted as cast, and reflected in the reported result without unauthorized alteration.

That makes integrity a property of the whole election system, including the physical process, the software used for tabulation and reporting, the chain of custody around ballots and devices, and the audit records used to confirm that outcomes match the underlying evidence. A failure in any one layer can weaken trust in the final result even if the other layers are sound.

Trust, Verification, and Auditability

Trustworthy elections depend on verification that can be repeated by independent parties. In practice, that means clear voter eligibility checks, controlled ballot issuance, accurate record keeping, and audit trails that support later review. The stronger the auditability, the easier it is to detect mismatches between reported totals and source records.

Verification also needs to be resilient to error, not just malice. If ballots, logs, or tally data are incomplete or inconsistent, the result can become difficult to defend even without proof of manipulation. For that reason, election integrity is closely tied to transparency, record retention, and procedures that allow recounts, reconciliation, and post-election review.

Where Manipulation and Failure Can Occur

Election systems can fail through impersonation, ballot stuffing, unauthorized system changes, insider abuse, misconfiguration, chain-of-custody breaks, or reporting errors. Modern election infrastructure also inherits digital risks, especially where tabulation, scanning, transmission, or public result publication depend on connected systems.

These weaknesses matter because election integrity is only as strong as the least controlled step in the process. Even a small compromise, for example in result reporting or device configuration, can create outsized doubt about the legitimacy of the outcome if the system cannot prove what happened.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Election integrity depends on governing risk to trust, accuracy, and resilience across the election process.
PR.AA-01 — Identity and Credential Management Integrity depends on strong identity assurance for voter, official, and system access where access governs election actions.
DE.CM-01 — Monitoring and Detection Auditable election processes require monitoring that can detect unauthorized changes, tampering, or reporting anomalies.
Recommendation — Establish a risk management strategy for election systems and align controls to integrity, auditability, and recovery. Enforce identity and credential controls for all election administration and system access paths. Monitor election systems and logs for anomalous changes, tampering, and reporting discrepancies.
CIS Controls v8 6.1 — Establish and Maintain an Asset Inventory Integrity depends on knowing which devices, systems, and records are in scope for counting and reporting.
8.1 — Establish and Maintain Audit Log Management Auditable elections require logs that support verification, reconciliation, and detection of unauthorized changes.
5.2 — Establish and Maintain a Secure Configuration Process Secure configuration is central to preventing unauthorized changes in election technology and reporting systems.
Recommendation — Maintain a complete inventory of election devices, systems, and records subject to integrity controls. Collect and protect logs needed to reconstruct and validate election actions and result reporting. Lock down election system configurations and validate changes before they affect counting or reporting.
OWASP Non-Human Identity Top 10 NHI-02 — Secrets and Credential Management Election systems often depend on machine credentials and keys for reporting and service access that must be protected from misuse.
NHI-07 — Privilege Management Election technology integrity is weakened when service or administrative accounts can alter results or configuration beyond necessity.
NHI-08 — Third-Party and Supply Chain Risk Election infrastructure often depends on vendors and integrators whose components can affect integrity and trust.
Recommendation — Protect machine credentials and keys that secure election reporting, scanning, or transmission services. Restrict privileged access so election services can only perform the actions they truly need. Assess third-party components and integration paths that could influence election integrity or result reporting.

Practitioner Guidance

Why practitioners should care: Election integrity is ultimately a confidence problem as much as a technical one. Election administrators, auditors, and system owners should treat every control that affects eligibility, ballot handling, counting, and reporting as part of a single integrity boundary.

Common misunderstanding: Strong security at the tabulator or reporting layer is not enough if ballot issuance, custody, or audit reconciliation is weak. Integrity has to be demonstrable end to end, not assumed from one protected component.

Practitioner takeaway: Design the process so independent verification can confirm the result even when one subsystem is questioned.

Risk and Threat Considerations

Election integrity is exposed to both deliberate interference and ordinary process failure. The main risk is not only that someone changes a result, but that they create enough ambiguity, missing evidence, or inconsistent records to make the result hard to trust.

Failure mechanism: Weak identity checks, poor chain of custody, altered configuration, or incomplete auditability can allow impersonation, unauthorized changes, or irreconcilable count discrepancies. When those controls fail, the system may still produce a result, but it becomes much harder to prove that the result is authentic.

Impact: The consequence is disputed outcomes, reduced public trust, costly recounts, legal challenge, and in severe cases a prolonged inability to certify the election with confidence.