Category Overview

Operational Security — Election Security Glossary

53 election security terms in the Operational Security category, with definitions sourced from NIST, CISA, EAC, and 30+ authoritative documents.

Browse all 53 terms in Operational Security

Default Classification

Classification reflecting the highest classification being processed in an information system.

Medium consensus2 sources

Disaster Recovery Plan (drp)

1. Management policy and procedures used to guide an enterprise response to a major loss of enterprise capability or damage to its facilities.

Medium consensus2 sources

End Item Accounting

Accounting for all the accountable components of a COMSEC equipment configuration by a single short title.

Medium consensus2 sources

Failure Control

Methodology used to detect imminent hardware or software failure and provide fail safe or fail soft recovery.

Medium consensus2 sources

Fill Device

A COMSEC item used to transfer or store key in electronic form or to insert key into KYK-13, and KYK-15.

Medium consensus2 sources

Hazard

A natural or man-made source or cause of harm or difficulty.

Medium consensus2 sources

Hot Site

A fully operational offsite data processing facility equipped with hardware and software, to be used in the event of an information system disruption.

Medium consensus2 sources

Operational Exercise

An action-based exercise where personnel rehearse reactions to an incident scenario, drawing on their understanding of plans and procedures, roles, and responsibilities.

Medium consensus2 sources

Operational Key

Key intended for use over-the-air for protection of operational information or for the production or secure electrical transmission of key streams.

Medium consensus2 sources

Operational Waiver

Authority for continued use of unmodified COMSEC end-items pending the completion of a mandatory modification.

Medium consensus2 sources

Periods Processing

1. A mode of system operation in which information of different sensitivities is processed at distinctly different times by the same system, with the system being properly purged…

Low consensus2 sources

Perishable Data

Information whose value can decrease substantially during a specified time.

Medium consensus2 sources

By ESG Editorial Team · Drawing on CISA operational guidance, EAC checklists, and 25+ sources on election-day procedures

Operational security is the set of day-to-day practices, procedures, and habits that keep election operations running safely. Unlike a firewall or an encrypted protocol, operational security is not a single product. It is a culture: the way a county office handles a phone call, how a vendor ships a laptop, the procedure a poll worker follows when opening a polling place at 6 a.m.

Why this category matters for election security is that most failures are not the result of sophisticated attacks. They are the result of someone being tired, being misled, or being in a hurry. A strong operational security program builds in double-checks, time for verification, and procedures that work even when the people executing them are new, stressed, or unsure.

The federal government, through the Cybersecurity and Infrastructure Security Agency and the Election Assistance Commission, publishes operational guidance for election offices. That guidance typically covers physical security, cyber hygiene, phishing awareness, and incident planning. State election directors and professional associations add their own layers, often focused on poll worker training and chain of custody procedures.

The terminology in this category reflects the everyday nature of the work. The concepts here are not abstract. They describe what a county IT director does on a Monday morning, or what a poll worker does when a voter disputes a provisional ballot.

How These Terms Relate

These concepts together describe the practical, day-to-day security of running an election. Operational security is where cybersecurity and physical security meet procedure, training, and culture. Chain of custody, two-person integrity, and physical access controls are not new inventions. They are practices that have governed sensitive operations (banking, military logistics, public accounting) for decades. The terminology here adapts that lineage to the specific demands of running a fair, accurate, and defensible election.

Related categories

Can't find the right category?

Search the full glossary, or browse every term alphabetically instead.