VEleS

By Steph4
12345678910111213141516171819202122
In The Matter OfVEleS
Exhibit A
Scroll to open

VEleS

SR 161.116 — Federal Chancellery Ordinance of 25 May 2022 on Electronic Voting (VEleS).

English is not an official language of the Swiss Confederation. This translation is provided for information purposes only and has no legal force. English consolidation of 1 July 2022, which is also the date of the current binding text.

Preamble

The Swiss Federal Chancellery (FCh), based on Articles 27e paragraph 1bis, 27g paragraph 2, 27i paragraph 3 and 27l paragraphs 3 and 4 of the Ordinance of 24 May 1978 on Political Rights (PoRO), ordains:

SR 161.11

Art. 1 Subject matter

This Ordinance regulates the requirements for authorising electronic voting trials.

Art. 2 Definitions

1 In this Ordinance: a. system is the generic term for all the software and infrastructures that are used to conduct electronic ballots; b. online system means the part of the system that is used to verify eligibility to vote, to cast the encrypted vote and to store the encrypted vote; c. the trustworthy part of the system is the part of the system that includes one or more groups of control components; the trustworthiness of this part of the system arises from the fact that misuse can be detected even if only one of a group’s control components is functioning correctly; d. control components are separate components of the system that are designed in a variety of ways, operated by different persons and secured by special means; e. system operator means the authority or private company that operates and maintains the online system at a ballot as directed by the canton; f. operation means any action, including maintenance, with a technical, administrative or legal aspect and related mana

Art. 3 Basic requirements for the authorisation of electronic voting for the individual ballots

Authorisation is required for each individual ballot; it is granted if the following requirements are met: a. The system is designed and operated so as to guarantee verifiable, secure and trustworthy electronic voting. b. The system is easy to use for the voters; account must be taken of the special needs of all voters wherever possible. c. The system and the operational procedures are designed and documented so that the details of the technical and organisational procedures can be checked and understood. d. The public have access to information appropriate to the addressees on how the system works and its operational processes, and there are incentives for experts among the public to participate.

Art. 4 Risk assessment

1 The canton shall conduct a risk assessment in which it demonstrates and justifies that the security risks in its area of responsibility are sufficiently low. The level of public trust in and acceptance of electronic voting must also form part of the assessment. 2 It shall check whether it can itself assess risks within the field of activity of its service providers and to what extent separate risk assessments by these service providers are required. If necessary, it shall request these separate risk assessments. 3 The risk assessments cover the following security objectives: a. the accuracy of the result; b. preserving voting secrecy and excluding premature partial results; c. availability and operability of the voting system; d. protecting personal information relating to voters; e. protecting information intended for voters from manipulation; f. ensuring that evidence of voting behaviour is not maliciously exploited. 4 Each risk must be identified and clearly described on the basis

Art. 5 Requirements for complete verifiability

1 It must be possible to detect any manipulation that leads to a falsification of the result while preserving voting secrecy (complete verifiability). This is considered to be the case if requirements for individual and universal verifiability are met. 2 The requirements for individual verifiability are as follows: a. The person voting is given the opportunity to ascertain whether the vote as entered on the user device has been manipulated or intercepted on the user device or during transmission; to this end, the person voting receives proof that the trustworthy part of the system (Art. 8) has registered the vote as it was entered by the person voting on the user device as being in conformity with the system; proof of correct registration is provided for each partial vote. b. A voter who has not cast his or her vote electronically can request proof after the electronic voting system is closed and within the statutory appeal deadlines that the trustworthy part of the system has not regi

Art. 6 Soundness of the proofs

The soundness of the proofs under Article 5 is based on the trustworthiness: a. of the trustworthy part of the system for proofs under Article 5 paragraphs 2 and 3; b. of the procedure for generating and printing the voting papers for proofs under Article 5 paragraph 2; and c. of the technical aids used by the auditors for the audit for proofs under Article 5 paragraph 3.

Art. 7 Preservation of voting secrecy and exclusion of premature partial results

The trustworthiness of: a. the trustworthy part of the system; b. the procedure for generating and printing the voting papers; is decisive in preserving voting secrecy and excluding premature partial results within the infrastructure.

Art. 8 Requirements for the trustworthy part of the system

1 The trustworthy part of the system includes one or more groups of control components. 2 Even if only one of the control components in each group functions correctly, the proof is still sound (Art. 6) and voting secrecy is still preserved (Art. 7). 3 The trustworthiness of the trustworthy part of the system is guaranteed by the diverse design of the control components and the independence of their operation and supervision.

Art. 9 Additional measures to minimise risks

If the risks are not sufficiently low despite the measures taken, additional measures must be taken to minimise risks. This applies in particular even if all the requirements of the Annex have already been met.

Art. 10 Requirements for examination

1 Independent entities commissioned by the Federal Chancellery shall examine: a. the cryptographic protocol (Annex No 26.1); b. the system software (Annex No 26.2); c. the security of infrastructure and operation (Annex No 26.3); d. the protection against attempts to infiltrate the infrastructure (Annex No 26.4). 2 The canton shall ensure that the system operator has an information security management system (ISMS) and this is examined by independent entities (Annex No 26.5). The ISMS shall as a minimum comprise the system operator’s processes and infrastructure that are relevant to achieving the security objectives. 3 The canton shall ensure that the Federal Chancellery and the independent entities that it commissions to conduct the examinations under paragraph 1 are given access to the system and the required documents. 4 The authorities responsible for the examinations under paragraphs 1 and 2 shall publish the evidential documents and certificates. Further documents must also be pu

Art. 11 Disclosure of the source code and of the documentation on the system and its operation

1 The canton shall ensure that the following documents are published: a. the source code of the system software including files with relevant parameters; b. evidence that the machine-readable programmes were generated from the published software source code; c. the software documentation; d. the development process documentation; e. instructions and other documents that experts require to be able to compile, execute and analyse the system on the basis of the source code within their own infrastructure; f. technical specifications of the main components of the system; g. the process documentation for operating, maintaining and securing the system; h. information on and descriptions of known flaws. 2 The following need not be published: a. the source code for third-party components such as operating systems, databases, web and application servers, rights management systems, firewalls or routers, provided they are widely used and regularly updated; b. the source code for portals of author

Art. 12 Disclosure modalities

1 The documents to be published under Article 11 must be drawn up and documented in such a way that they are easy to read and analyse. 2 In order to facilitate their examination by the public, the documents must be: a. available online in a simple process that is free of charge and does not require registration; and b. made available in good time before the planned use of the system. 3 Any person may examine, modify, compile and execute the source code for ideational purposes and write reports thereon. They may publish reports and findings relating to flaws. They may have discussions with others, in particular in order to identify flaws, and in doing so may quote from the published information. 4 The proprietor of the source code may: a. permit the source code to be used for other purposes; b. set specific conditions for submitting suggestions for improving the system; it may call for flaws to be reported without delay and specify a date before which reports on suspected flaws may not

Art. 13 Public involvement

1 The canton shall designate a body to which interested persons may submit suggestions for improving the system, including: a. suggestions relating to flaws in the documents published under Article 11; b. suggestions on the basis of attempts to intrusion in the online system as part of public tests. 2 The body under paragraph 1 shall evaluate the suggestions and inform the person concerned of its assessment and of any measures taken based on the suggestion. This information shall be published. 3 The canton shall ensure that suitable financial reward is given for suggestions that relate to security and that help to improve the system.

Art. 14 Responsibility for running the ballot with electronic voting correctly

1 The canton bears overall responsibility for running the ballot with electronic voting correctly. 2 It must carry out important tasks itself. It may delegate the development of the software used, operational tasks and communication on questions about how the system works to external organisations. 3 The canton shall appoint a body at cantonal level that bears overall responsibility, and for the following tasks in particular: a. drawing up general information security policy; b. drawing up information classification and processing policy for the information resources identified; c. drawing up risk management policy; d. defining and implementing measures to ensure compliance with the policies in letters a–c; e. appointing a system operator and drawing up the requirements for its supervision and monitoring; f. setting the deadlines for carrying out critical actions and operations; g. supervising and monitoring the system operator’s work; h. supporting and instructing the auditors; i. ass

Art. 15 Application documents

1 Applications submitted under Article 27e PoRO must be accompanied by information on the planned use of the electronic voting channel and documents on how the legal requirements are met. These include the following in particular: a. up-to-date risk assessments under Article 4, including the information necessary to make them comprehensible; b. certificates and their attachments produced in examinations under Article 10 paragraph 2 and information on their publication in accordance with Article 10 paragraph 4; c. information on the disclosure of the documents under Article 11 and suggestions from the public under Article 13; d. reports on tests that the canton has carried out, and indications of existing flaws in the system; e. justification and any measures regarding exemptions under Article 16 paragraph 2. 2 Reference may be made to documents under paragraph 1 that the Federal Chancellery has already received and which are still valid.

Art. 16 Further provisions

1 The detailed technical and administrative requirements for electronic voting are regulated in the Annex. 2 The Federal Chancellery may in exceptional cases exempt a canton from meeting individual requirements, provided: a. the requirements that have not been met are indicated in the application; b. reasonable justification is brought forward for allowing an exemption; and c. the canton describes any alternative measures and justifies in reference to the risk assessment why it regards the risks as sufficiently low.

Art. 17 Repeal of another enactment

The FCh Ordinance of 13 December 2013 on Electronic Voting is repealed.

[AS 2013 5371; 2018 2279]

Art. 18 Commencement

This Ordinance comes into force on 1 July 2022.