[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8KAtUXWEdG9kb_3WY5mfSaBnmy5br8kytYPvFv1FP8g":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"1453c5da-e032-422d-99fb-079a450121b9","convicted-election-system-criminal-considered-for-election-role","cb82d0e5-fcb3-4989-9e61-30ee60e1602a","Convicted Election System Criminal Considered for Election Role","Shasta County's consideration of Tina Peters — a convicted felon found guilty of identity theft and stealing voting system software — for an election administration role represents a critical failure in personnel vetting and access control governance. Granting individuals with demonstrated malicious intent access to sensitive election infrastructure creates unacceptable risk to democratic systems and public trust. Background check and disqualification policies must explicitly address criminal convictions related to the specific role's trust domain, not just general criminal history. A sentence commutation does not erase the underlying threat model posed by someone who has shown both capability and willingness to compromise election systems. This case illustrates how human insider threats can bypass technical controls entirely when administrative hiring safeguards are absent.","**Immediate actions:**\n- Implement mandatory criminal background screening policies that automatically disqualify candidates convicted of crimes directly related to the role's responsibilities.\n- Establish a formal review board including legal, security, and ethics stakeholders for any hiring decisions involving access to critical election infrastructure.\n\n**Long-term improvements:**\n- Develop a role-based access policy framework that maps job functions to required trust levels, with explicit disqualifying criteria tied to relevant criminal history.\n- Engage state election authorities and secretaries of state to create statewide minimum vetting standards for all election administration personnel.\n- Conduct regular audits of personnel with privileged access to election systems to ensure continued eligibility and trustworthiness.\n\n**Detection & oversight measures:**\n- Require ongoing monitoring and periodic re-vetting of all employees with access to election systems, not just at the point of hire.\n- Establish whistleblower channels so staff and the public can report concerns about personnel fitness without fear of retaliation.",[12,13,14,15,16,17,18,19],"NIST SP 800-53 PS-2 (Position Risk Designation)","NIST SP 800-53 PS-3 (Personnel Screening)","NIST SP 800-53 AC-2 (Account Management)","CIS Control 6: Access Control Management","CISA Election Security Guidelines – Personnel Security","EAC Voluntary Voting System Guidelines (VVSG) – Physical & Personnel Security","NIST SP 800-76 (Insider Threat Program)","ISO\u002FIEC 27001 Annex A.7 – Human Resource Security","published","2026-08-19T16:20:17.632667+00:00","2026-08-19T16:20:17.318+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fcyberscoop.com\u002Fshasta-county-elections-tina-peters\u002F","a-california-county-wants-to-hire-tina-peters-to-help-run-its-elections-2ab3f1","A California county wants to hire Tina Peters to help run its elections",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",[]]