Ohio research subcontract: HTML reading copy
- Agreement effective:
- Reading copy reviewed:
About this reading copy
This is a structured HTML reading copy of the 25-page Sponsored Research Subcontract Agreement between The Trustees of the University of Pennsylvania and SysTest Labs, Incorporated, for work related to the Ohio Risk Assessment Study. It includes the agreement, appendices, and the labels and questions in its blank forms. The blanks are described here but cannot be completed in this page.
The original PDF is preserved at its historical address. It is untagged. This reading copy is provided for access to the document’s contents and is not a signed, certified, or legal replacement for the PDF. The PDF contains a prime-contract placeholder and some internal references that appear inconsistent: clause 20.3 points to Appendix A, Exhibit 3 for the DMA declaration, while the declaration is headed Exhibit 4; the Confidentiality Agreement names a different subcontract date and says “between the Contractor and Contractor” in section 3.01. This copy preserves those words rather than supplying terms or legal interpretation.
Sponsored Research Subcontract Agreement
THIS AGREEMENT is effective this 24th day of September, 2007, by and between The Trustees of the University of Pennsylvania (hereinafter referred to as "Subcontractor") located at the Office of Research Services, 3451 Walnut Street P-221, Philadelphia, PA 19104-6205, and SysTest Labs, Incorporated, having a principal place of business at 216 16th Street, Suite 700, Denver, Colorado 80202 (hereinafter referred to as "Contractor").
RECITALS:
- The research program contemplated by this Agreement is of mutual interest and benefit to Subcontractor and Contractor, will further the multiple missions of Subcontractor (Instruction, Research, and Public Service) in a manner consistent with its status as a non-profit, tax-exempt, educational institution, and may derive benefits for Contractor, Subcontractor, and society by the advancement of science and engineering through discovery.
- Contractor has executed a contract with the State of Ohio to perform comprehensive voting machine testing for the State of Ohio (known as the “Ohio Risk Assessment Study”), and specifically for the Secretary of State of Ohio (hereinafter “Secretary”), and desires to engage Subcontractor to perform independent testing and research on voting systems used in the State of Ohio that will meet the needs of the Secretary and provide additional scientific perspective to the Ohio Risk Assessment Study.
- Subcontractor's research capabilities reflect a substantial public investment that Subcontractor, as a part of its mission as a private university, wishes to utilize in a cooperative research effort with Contractor in order to meet the above stated needs.
- This Sponsored Research Subcontract Agreement is a subcontract to Contractor’s agreement with the Secretary of State of Ohio, attached hereto as Appendix A, Exhibit 1 (the “prime contract”). Contained within the prime contract is a Statement of Work to be performed by research universities and/or business entities employing academics to complete the Ohio Risk Assessment Study. That Statement of Work is excerpted and attached hereto as Appendix A, Exhibit 2.
NOW, THEREFORE, in consideration of the promises and mutual covenants set forth below, the parties hereto agree to the following:
Article 1: Definitions
As used herein, the following terms shall have the following meanings:
1.1 "Project" shall mean the research set forth in the Statement of Work of Academic Teams attached hereto as Appendix A, Exhibit 3, to be conducted under the general direction of Dr. Patrick McDaniel of the Pennsylvania State University and, more specifically, the research to be conducted by the University of Pennsylvania under the direction of Dr. Matthew Blaze as Principal Investigator.
1.2 "Intellectual Property" shall mean certain inventions and/or discoveries conceived and/or reduced to practice in performance of this Project and resulting patents, divisions, continuations, or substitutions of such applications and all reissues thereof, upon which a Subcontractor employee or agent is a named inventor.
1.3 "Proprietary Information" shall mean any written information and data marked proprietary or confidential, or non-written information and data disclosed that is identified at the time of disclosure as proprietary and is reduced to writing and transmitted to the other party within fifteen (15) days of such non-written disclosure.
Article 2: Period of Performance
2.1 The period of performance shall begin on October 1, 2007 and shall terminate on January 7, 2008.
2.2 Subcontractor shall complete the Services ascribed to The University of Pennsylvania in the Statement of Work of Academic Teams attached hereto as Appendix A, Exhibit 3, no later than December 7, 2007, unless otherwise mutually agreed.
2.3 Subcontractor understands that prompt performance of all Services hereunder is required in order for the Secretary to prepare for administration of Ohio elections in 2008. Contractor, Subcontractor and the Ohio Secretary of State acknowledge that, in order to complete the Project by December 7, 2007, Subcontractor must receive requested reports, documentation/materials and equipment no later than October 5, 2007. Cost for transporting equipment and materials/documentation shall be borne by the Ohio Secretary of State.
2.4 In the event that any anticipated or actual delays in completing the project by December 7, 2007, are caused by failure to use best efforts by the Subcontractor or its employees or agents or any other cause within the reasonable control of Subcontractor, Subcontractor shall provide additional temporary personnel as may be requested by the Contractor or by the Secretary, and at no charge, in order to complete the assignment in a timely manner.
2.5 Subcontractor and Contractor shall not be responsible for any delays that are not due to the party’s fault or negligence or that could not have reasonably been foreseen or provided against. The delayed party will notify the other promptly of any material delay in performance and will specify in writing the proposed revised performance date as soon as practicable after notice of delay. In the event of any such excusable delay, the date of performance or of delivery will be extended for a period equal to the time lost by reason of the excusable delay. The delayed party must also describe the cause of the delay and what steps it is taking to remove the cause and must use best efforts to mitigate any delay.
Article 3: Research Work
3.1 Subcontractor shall use reasonable best efforts to undertake the work and activities ascribed to The University of Pennsylvania in the Statement of Work of Academic Teams attached hereto as Appendix A, Exhibit 3.
3.2 Subcontractor shall follow the procedures set forth in the security plan attached hereto as Appendix B, Exhibit 1, that has been prepared with the advice and consent of the Ohio Secretary of State and mutually agreed upon by Contractor and the Subcontractor. Subcontractor further agrees that each of Subcontractor’s agents, subcontractors, its employees and personnel who perform services for the Project will read and acknowledge having read the security plan, by executing the form attached hereto as Appendix B, Exhibit 3.
3.3 Subcontractor shall consult with personnel of the Secretary, including the Secretary’s Project Representative and Project Manager, identified in Article XIII, representatives of the prime contract, and other appropriate persons, agencies and instrumentalities as designated by the Secretary and/or as necessary to assure understanding of the work and will provide weekly summary updates.
3.4 Subcontractor shall use reasonable best efforts to complete the Project in accordance with professional and industry standards, in accordance with appropriate government regulations.
Article 4: Reports
4.1 The Principal Investigator shall cooperate with Contractor regarding the Project but, recognizing the desired independence of the parallel work being performed for the State of Ohio by Contractor and Subcontractor, periodic and final reports of Subcontractor’s work on the Project shall be independent of Contractor’s report of its work on the Project, and shall be provided directly to the Ohio Secretary of State.
4.2 Subcontractor agrees to the following report conditions:
- All specific data that could compromise the security of the voting system or that could compromise the proprietary rights of voting machine manufacturers shall be included in separate appendices to final reports and provided to the General Counsel to the Secretary for proprietary protection review.
- Contractor and Subcontractor shall not include ultimate recommendations as to whether a voting system should remain certified or have its certification withdrawn.
4.3 The Ohio Secretary of State shall make the final report on each voting system public within 45 days after it is submitted, subject only to redactions required to avoid compromising the security of the voting system or the vendor’s proprietary rights. No investigator or reviewer shall make or release any comments or other information about the processes, procedures, progress or findings of the voting system review or any draft or final report to any third party via any medium for 45 days from the submission of the final report to the Ohio Secretary of State, or until the final report is made public by the Secretary of State, whichever is sooner.
4.4 After 45 days from the submission of the final report provided to the Ohio Secretary of State, or until the final report is made public by the Secretary of State, whichever is sooner, the Subcontractor is free to publish in accordance with Article 7 of this Agreement and consistent with the Confidentiality Agreement, Appendix B, Exhibit 2.
Article 5: Fiscal Considerations
5.1 This is a cost reimbursable agreement. Total cost to Contractor shall not exceed Two Hundred Nine Thousand Nine Hundred and Forty dollars ($209,940.00). Subcontractor shall provide Contractor itemized invoices at least monthly and may simultaneously provide the Ohio Secretary of State copies of said invoices. Contractor shall forward copies of Subcontractor invoices to the Ohio Secretary of State and shall make payments to Subcontractor within thirty (30) days of receipt from the Secretary of funds representing reimbursement of Subcontractor’s costs. Subcontractor and Contractor may provide invoices to the Secretary via email to [email protected] or by facsimile transaction.
5.2 Travel expenses incurred by Subcontractor in connection with the Project shall be borne initially by the Subcontractor. To the extent not otherwise reimbursed and subject to the total dollar limitation set forth in Section 5.1, travel expenses incurred in connection with the Project shall be reimbursed by the Contractor in accordance with the reimbursement policies of the U.S. Government or law of the State of Ohio, whichever is in use by the Subcontractor.
5.3 Subcontractor shall retain title to any equipment purchased with funds provided by Contractor under this Agreement. Title to equipment owned by the Ohio Secretary of State but provided to Subcontractor for use during the Project shall remain with the Secretary.
5.4 Subcontractor will be provided voting systems (including hardware, software, source code, documentation and other proprietary and confidential items) for testing that may be the property of the Ohio Secretary of State, a voting machine manufacturing or retailer, or a county board of elections. Subcontractor agrees it shall abide by the terms of Appendix B, Exhibit 2, attached hereto and incorporated herein, regarding nondisclosure of confidential information; that it shall not retain any such voting systems after December 31, 2007; and shall return all such items to the Ohio Secretary of State no later than December 31, 2007.
5.5 In the event of early termination of this Agreement pursuant to Articles 10 and 19.2 hereof, Contractor shall pay all reasonable costs incurred and non-cancelable obligations incurred by Subcontractor as of the date of termination.
Article 6: Publicity
6.1 Neither party to this Agreement will use the name of the other party, nor of any member of the other party's employees, in any publicity, advertising, or news release concerning the work of this Subcontract without the prior written approval of an authorized representative of that party.
Article 7: Publication
7.1 The purpose of this Article, in conjunction with Article 8 – Confidentiality and Section 5.09 of the Confidentiality Agreement attached hereto as Appendix B, Exhibit 2, is to acknowledge the Subcontractor's public responsibility to freely disseminate scientific findings for the advancement of knowledge. Contractor, the Ohio Secretary of State and Subcontractor recognize that information based upon Research performed under this Agreement that includes proprietary information or that might be used to undermine election integrity should not be publicly disseminated. Similarly, Contractor, the Ohio Secretary of State, and Subcontractor recognize that the scientific results of the Project are subject to publication consistent with the obligations of the confidentiality provisions of this Agreement and that such scientific results of the Project may be presented in forums including, but not limited to, symposia or international, national or regional professional meetings, or published in vehicles such as books, journals, websites, theses, or dissertations.
Article 8: Confidentiality
8.1 Subcontractor shall execute the Confidentiality Agreement attached hereto as Appendix B, Exhibit 2, the terms of which have been prepared with the advice and consent of the Ohio Secretary of State; will assure the integrity and security of the Risk Assessment Study; and have been mutually agreed upon by the Ohio Secretary of State, Contractor and the Subcontractor. Subcontractor further agrees that each of Subcontractor’s agents, subcontractors, and its employees and personnel who perform services for the Project will read and acknowledge having read the confidentiality agreement by executing the form attached hereto as Appendix B, Exhibit 3.
Article 9: Intellectual Property
9.1 All inventions arising out of this Subcontract Agreement will be promptly disclosed to Contractor. Subcontractor shall not obtain or attempt to obtain patent coverage on Contractor-provided proprietary materials or information, without the express written consent of Contractor. All inventions, patent applications, or patents made during this Subcontract Agreement which name as an inventor at least one employee of Subcontractor shall be owned as follows:
- Inventions that involve the use of, composition of, or improvement to Contractor-provided proprietary materials or information, or a derivative, analogue thereof, shall belong to Contractor; and
- Inventions that cover a scientific process, technique, procedure, medium, device or other process that is not unique to processing Contractor's proprietary materials or does not derive from Contractor-provided materials or information shall be owned by Subcontractor. Contractor shall be given an option to negotiate a license thereto.
Article 10: Termination
10.1 Either party may terminate this Agreement upon thirty (30) days prior written notice to the other.
10.2 In the event that either party hereto shall commit any material breach of or default in any terms or conditions of this Agreement, and also shall fail to reasonably remedy such default or breach within thirty (30) days after receipt of written notice thereof, the non-breaching party may, at its option and in addition to any other remedies which it may have at law or in equity, terminate this Agreement by sending notice of termination in writing to the other party to such effect. Termination shall be effective as of the day of the receipt of such notice.
10.3 Termination of this Agreement by either party for any reason shall not affect the rights and obligations of the parties accrued prior to the effective date of termination of this Agreement. The rights and obligations of Article 8 of this Agreement shall remain in effect as specified in Appendix B, Exhibit 2.
Article 11: Independent Contractor
11.1 In the performance of project, Subcontractor shall be deemed to be and shall be an independent contractor.
11.2 Neither party hereto is authorized or empowered to act as agent for the other for any purpose and shall not on behalf of the other enter into any contract, warranty, or representation as to any matter. Neither party shall be bound by the acts or conduct of the other.
Article 12: Hold Harmless
12.1 Each party assumes all risks of personal injury, bodily injury including death, caused by the negligent acts or omissions of that party. Except as provided above, Contractor shall hold harmless Subcontractor against all claims and costs (including counsel fees) arising out of Contractor's use, commercialization, or distribution of information, materials or products that result in whole or in part from the research performed pursuant to this Agreement.
12.2 In conducting the Project some voting systems and/or equipment may be dissembled and may be rendered incapable of future use or operation. Subcontractor agrees to take reasonable measures to reassemble voting systems and/or equipment so as to enable their future use or operation. Should voting systems and/or equipment be rendered incapable of future use despite those reasonable measures, Subcontractor shall not be liable to Contractor or Secretary for repair or replacement of such voting systems and/or equipment.
Article 13: Recordkeeping and Audits
13.1 Subcontractor will keep all financial records in accordance with bookkeeping and recordkeeping procedures consistent with generally accepted accounting procedures consistently applied. Subcontractor will file documentation to support each action under this Agreement in a manner allowing it to be readily located. Subcontractor will keep all Project-related records and documents at its principal place of business or at its office where the work was performed.
13.2 Subcontractor will keep a separate account for the Project (the “Project Account”). All payments made from the Project Account will be only for obligations incurred in the performance of this Agreement and will be made in accordance with Article 5.
13.3 During the term of this Agreement and for three (3) years after payment of Subcontractor’s final billing statement, on reasonable notice and during customary business hours, the Secretary may audit Subcontractor’s records and other materials that relate to the Project at Subcontractor’s site and shall be coordinated with Subcontractor’s Office of Research Services. This audit right will also apply to the Secretary’s duly authorized representatives and any person or organization providing financial support for the Project.
13.4 Unless it is impracticable to do so, all records related to Subcontractor’s performance under this Agreement must be kept in a single location, either at Subcontractor’s principal place of business or its place of business where the work was done. If this is not practical, Subcontractor will assume the cost of collecting, organizing, and relocating the records and any technology needed to access the records to Subcontractor’s office nearest Columbus, Ohio, whenever the Secretary or anyone else with audit rights requests access to Subcontractor’s Project records. Subcontractor will do so with all due speed, not to exceed five (5) business days.
13.5 Subcontractor agrees that if any audit reveals any material deviation in subcontractor’s services or deliverables from the Scope of Work set forth herein, any misrepresentation, or any overcharge to the Contractor, the Secretary will be entitled to recover damages, as well as the cost of the audit, directly from the Subcontractor as if the Secretary had retained the services of the subcontractor directly.
Article 14: Notices
14.1 Notices, invoices, communications, and payments hereunder shall be deemed made if given by overnight courier or by registered or certified envelope, post prepaid, and addressed to the party to receive such notice, invoice or communication at the address given below or such other address as may hereafter be designated by notice in writing:
- If to Contractor
- SysTest Labs, Inc.; 216 16th Street, Suite 700; Denver, Colorado 80202; Attn: Mr. Brian Phillips, President. Phone: 303-575-6881. Fax: 303-861-6882. Printed “Email”: www.systest.com.
- If to Subcontractor
- Deborah M. Fisher, Director of Preaward Administration, Office of Research Services; 3451 Walnut Street P-221; Philadelphia, PA 19104-6205. Phone: 215-746-0234. Fax: 215-898-9708. Email: [email protected].
- If Technical Issue
- Dr. Matthew Blaze, Professor – Computer and Information Science, University of Pennsylvania; 3330 Walnut Street, Room 611; Philadelphia, PA 19104. Phone: 212-573-2696. Email: [email protected].
14.2 Notice given pursuant to this Article shall be effective as of the day of receipt of notice.
Article 15: Governing Law
15.1 Both parties agree to comply with all applicable federal, state, and local laws and regulations in the performance of this Project, as well as any requirements under any applicable protocol or statement of work. This Agreement shall be governed and construed and the rights of the parties determined in accordance with the laws of the State of Ohio, without reference to the choice of law provisions thereof.
Article 16: Dispute Resolution
16.1 Any and all claims, disputes or controversies arising under, out of, or in connection with this Agreement, which the parties hereto shall be unable to resolve within sixty (60) days, shall be mediated in good faith. The party raising such dispute shall promptly advise the other party of such claim, dispute or controversy in writing which describes in reasonable detail the nature of such dispute. By not later than five (5) business days after the recipient has received such notice of dispute, each party shall have selected for itself a representative who shall have the authority to bind such party, and shall additionally have advised the other party in writing of the name and title of such representative. By not later than ten (10) business days after the date of such notice of dispute, the party against whom the dispute shall be raised shall select a mediation firm in Pennsylvania and such representatives shall schedule a date with such firm for a mediation hearing not to exceed one (1) day in length, and less where applicable. The parties shall enter into good faith mediation and shall share the costs associated with participating in the mediation equally. If the representatives of the parties have not been able to resolve the dispute within fifteen (15) business days after such mediation hearing, the parties shall have the right to pursue any other remedies legally available to resolve such dispute.
16.2 Notwithstanding the foregoing, nothing in this clause shall be construed to waive any rights or timely performance of any obligations existing under this Agreement.
Article 17: General Provisions
17.1 Non-assignability –The rights and obligations of the parties under this Agreement shall not be assignable without written permission of the other party.
17.2 Severability -- If any provision hereof is held unenforceable or void, the remaining provisions shall be enforced in accordance with their terms.
17.3 Entire Agreement -- This Agreement contains the entire and only agreement between the parties respecting the subject matter hereof and supersedes or cancels all previous negotiations, agreements, commitments and writings between the parties on the subject of this Agreement. Should processing of this Agreement require issuance of a purchase order or other contractual document, all terms and conditions of said document are hereby deleted in entirety unless specifically incorporated by reference in said subsequent agreement. This Agreement may not be amended in any manner except by an instrument in writing signed by the duly authorized representatives of each of the parties hereto.
17.4 Order of Precedence – If any conflicts or discrepancies should arise in the terms and conditions of this Subcontract Agreement and the prime contract, Appendix A, Exhibit 1, this Subcontract Agreement shall govern.
Article 18: Insurance
18.1 The Subcontractor is responsible for procuring appropriate insurance coverage at its own expense throughout the term of this Agreement including, where applicable, Worker’s compensation insurance; commercial general liability insurance coverage for bodily injury, personal injury, wrongful death; and commercial automobile liability insurance.
Article 19: Certification of Funds
19.1 It is expressly understood by the parties that none of the rights, duties or obligations described in this Agreement shall be binding on either party until all statutory provisions under the Ohio Revised Code, including but not limited to Section 126.07 of the Ohio Revised Code, have been complied with and until such time as all necessary funds to support the prime contract between Contractor and the Secretary are made available and forthcoming from the state legislature and/or appropriate state agencies, and when required, such expenditure of funds is approved by the Controlling Board of the State of Ohio.
19.2 The parties acknowledge that the Secretary of State of Ohio may terminate the prime contract between the Contractor and the Secretary for her convenience and without cause or if the Ohio General Assembly fails to appropriate funds for any part of the Project. Should the Secretary terminate the prime contract for her convenience, Subcontractor will be entitled to compensation for any work on the Project that Subcontractor has performed before the termination, in accordance with Article 5.5 hereof. Such compensation will be the Subcontractor’s exclusive remedy in the case of a termination of the prime contract for the convenience of the Secretary and will be available to Contractor only once Contractor has submitted an invoice for such, with the invoice reflecting the amount determined to be owing to Subcontractor.
Article 20: Certification of Compliance with Ohio Laws
20.1 Subcontractor shall require its employees or agents performing under this Agreement to certify to the best of their knowledge that they are currently in compliance and will continue to adhere to the requirements of Ohio Ethics Laws as provided by Sections 102.03 and 102.04 of the Ohio Revised Code.
20.2 Subcontractor hereby certifies to the best of its knowledge that all applicable parties listed in Division (I)(3) and (J)(3) of Ohio Revised Code §3517.13 are in full compliance with Divisions (I)(1) and (J)(1) of Ohio Revised Code §3517.13.
20.3 The Subcontractor shall comply with the requirements of Ohio Revised Code §2909.33 including execution of the Ohio Homeland Security Declaration of Material Assistance (“DMA”), attached as Appendix A, Exhibit 3. Information concerning the Ohio DMA may be found at the following website: http://www.homelandsecurity.ohio.gov/dma/dma.asp
IN WITNESS WHEREOF, the parties hereto have caused these presents to be executed in duplicate as of the day and year first above written.
The PDF has two unsigned execution columns with the following labels and blank lines:
- By an authorized official of Subcontractor
- Blank signature line; Name: blank; Title: blank; Date: blank.
- By an authorized official of Contractor
- Blank signature line; Name: blank; Title: blank; Date: blank.
Appendix A, Exhibit 1: Prime contract placeholder
[Copy of Prime Ohio SOS-Systest Contract—to be incorporated as a .pdf copy of the signed contract ]
The source PDF contains only the bracketed placeholder above on page 9; it does not include the prime contract copy.
Appendix A, Exhibit 2: Statement of Work of Academic Teams excerpted from the prime contract
Between SysTest Labs, Inc. and the Secretary of State of Ohio.
Article II: STATEMENT OF WORK
2.02 Contractor and the Academics shall undertake the work and activities set forth below (the “Services” or the “Project”) consistent with the methodologies more fully described in Exhibits 2 through 6 of this Contract:
Tasks
The source excerpt marks omitted prime-contract material here with three asterisks.
Task 2: Perform “Red Team” Vulnerability Testing (Responsibility of Academics)
a. Perform a security evaluation by attempting to penetrate each device of a certified voting system currently in use in the State of Ohio, as more specifically identified in Exhibit 1 of this Agreement, and each device of a voting system not currently deployed in Ohio but that may be certified for use in Ohio elections in 2008, also identified in Exhibit 1, with the goal of understanding specifically defined conditions under which unauthorized changes to the function of the systems are possible or the election results may be compromised. The evaluation should indicate what operational and system controls exist that can prevent, detect, or correct such unauthorized changes, the extent of inaccuracies that can be introduced by each compromise, and the needed resources, time and expertise needed to create such a compromise.
b. Report the results of each phase of the evaluation and the corrective measures available to prevent penetration of the device in the future.
The source excerpt marks omitted prime-contract material here with three asterisks.
Task 4: Audit of Prior Voting System Assessments and Source Code Review (Responsibility of Academics)
a. Assess the current risk related to issues identified and recommendations made in prior reports and reassessments of voting systems currently used in Ohio, as identified in Exhibit 1.
b. Conduct a source code review—static and/or dynamic—of the ballot casting and tabulation software to determine the level of effort needed to insure a specific level of confidence in the ability of the code to produce accurate results. Produce an analysis of the required amount of effort to identify risks to election integrity.
Deliverables
1. Weekly Progress Reports. At the end of each week during performance of the Project, Contractor and Academics shall separately and independently prepare and submit to the Secretary written reports detailing progress in testing and assessing during the week. In addition, Contractor shall ensure that all Academics are advised of this contractual responsibility in all subcontract agreements. The report should give such details as:
- Percentage of assessment completed during the week preceding the report;
- Issues discovered during the week’s testing, if any, along with proposed solutions; and
- Percentage of assessment anticipated to be completed the following week.
2. System-Specific Reports. Upon completion of the tasks identified in Section 2.01 as to each voting system identified in Exhibit 1, Contractor and Academics shall separately and independently submit to the Secretary a written report specific to that system. In addition, Contractor shall ensure that all Academics are advised of this contractual responsibility in all subcontract agreements. The report shall include findings resulting from performance of such tasks, and
- Issues or areas of concern uncovered during the assessment, if any;
- Contractor’s estimation of the level of risk for each of the tasks; and
- Suggestions for improvement or ways to mitigate the risks involved.
3. Final Risk Assessment Report. Upon final completion of Tasks 1, 3, and 5 as set forth in Section 2.01, but no later than November 30, 2007, Contractor shall submit to the Secretary a final written report assessing existing risks to election integrity associated with Ohio’s current voting systems as disclosed during performance of Tasks 1, 3 and 5. In addition, Academics, upon final completion of Tasks 2 and 4 set forth in Section 2.01 and further defined in Exhibits 3 through 6, but no later than November 30, 2007, agree to submit to the Secretary a final written report assessing existing risks to election integrity associated with Ohio’s current voting systems in all subcontract agreements. The report shall, at a minimum, meet the follow requirements:
- Provide an overview of the risk assessment study, detailing methods used, equipment and software tested, and other pertinent details;
- Provide a breakdown and comparison of the results for each voting system based on the task identified above, detailing individual and shared threats or risks to system integrity and whether a review of any or all of the systems’ source code is warranted; and
- Provide suggestions or proposals to eliminate or mitigate potential risks to the integrity of Ohio’s election systems.
Appendix A, Exhibit 3: Statement of Work of Academic Teams
Pennsylvania State University
The Pennsylvania State University team will perform penetration testing and source code analysis for the Hart and Premiere systems for all versions specified in the Ohio RFP and its addenda. The analyses will primarily evaluate the degree to which recent vendor software upgrades address or mitigate the security weaknesses reported in previous voting studies, and will be directed by the team lead, Professor Patrick McDaniel. The emphasis of this analysis will be on the results of the California Top-To-Bottom (TTB) review released in August of 2007. The PSU team will extend the analysis of software upgrades and mitigations to investigate potential related flaws or vulnerabilities as indicated by initial findings. The team will work closely with the Cleveland State document review team to aid their evaluation of risk, and support the efforts of the other teams as needed and possible. The primary work product of the effort will be a report documenting the factual threats, vulnerabilities, and available counter-measures revealed in the study. In identifying counter-measures, the technical teams will consider election procedures and processes currently implemented in Ohio as communicated to them through consultation and collaboration with the Documentation and Procedures Review teams. This report will be delivered to the Ohio Secretary of State’s office no later than December 7th, 2007. The technical evaluation Principal Investigator (PI), Professor Patrick McDaniel, will coordinate evaluation activities of all teams. Professor McDaniel will serve as the technical point of contact for the effort and liaison between the teams and the Secretary of State’s office.
University of Pennsylvania
The University of Pennsylvania team will focus on the source-code evaluation of the Election Systems and Software (ES&S) systems identified in the Ohio RFP and its addendum. This effort will not be restricted to source-code analysis, but may include red-teaming exercises or other security evaluation methods as deemed appropriate by the local team lead, Professor Matt Blaze. Similar to the goals of the recently completed California TTB review, the primary goal of the study will be to identify flaws, if any, in the ES&S system that may affect the accuracy, auditability, availability, integrity, reliability, security, or ballot secrecy of the election process. The team will work with and support the efforts of the other teams as needed and possible. The central work product of that evaluation will be a report documenting the factual threats, vulnerabilities, and available counter-measures uncovered in the study. In identifying counter-measures, the technical teams will consider election procedures and processes currently implemented in Ohio as communicated to them through consultation and collaboration with the Documentation and Procedures Review teams. This report will be delivered to the Ohio Secretary of State’s office no later than December 7th, 2007.
WebWise Security, Inc
The WebWise team will focus on the penetration (also known as red-teaming) evaluation of the Election Systems and Software (ES&S) system identified in the Ohio RFP and its addendum. This effort will not be restricted to penetration testing only, but may include source-code analysis or other security evaluation methods deemed appropriate by the local team lead, Professor Giovanni Vigna. Similar to the goals of the recently completed California TTB review, the primary goal of the study will be to identify flaws, if any, in the ES&S system that may affect the accuracy, auditability, availability, integrity, reliability, security, or ballot secrecy of the election process. The team will work with and support the efforts of the other teams as needed and possible. The central work product of that evaluation will be a report documenting the factual threats, vulnerabilities, and available counter-measures uncovered in the study. In identifying counter-measures the technical teams will consider election procedures and processes currently implemented in Ohio as communicated to them through consultation and collaboration with the Documentation and Procedures Review teams. This report will be delivered to the Ohio Secretary of State’s office no later than December 7th, 2007.
Cleveland State University
The Cleveland State University (CSU) Center for Election Integrity will staff three Documentation and Procedures Review teams. Each team will be assigned to study one of the three Ohio voting systems. Each team will assess the adequacy of vendor operational guidance for local elections officials with regard to specific criteria (including security, accuracy, auditability, reliability, usability, ballot secrecy, and managerial contingency planning). Each vendor’s documentation will also be evaluated for its support of the State of Ohio voting machine certification process and for independent testing, in light of the applicable regulatory standards. Document review teams will promptly provide research results to their penetration test and source code analysis team counterparts and address related documentation and regulatory research tasks as they may develop and as time permits.
To better understand operational risks and risk management procedures, the Documentation and Procedures teams will analyze a sample of Board of Election (BOE) system and audit logs generated in recent elections. Additionally, in coordination with the BOE Directors and the Secretary of State staff, a small team may conduct on-site interviews and other agreed-upon activities accompanied by Secretary of State Regional Liaisons ("field staff") at the Boards of Elections of the following Ohio counties: Franklin, Fairfield, Cuyahoga, Montgomery, Allen, Lorain, Jackson, Belmont, Warren, Hamilton, and Licking.
Each of the final technical reports will be focused on a specific system and include an inventory of locally identified risks and corresponding operational and internal controls. If gaps are identified, the teams may propose procedural remedies in the final report. The draft reports will be developed under the supervision of the CSU Principal Investigator, Professor Candice Hoke, by November 25, 2007, and the final reports will be submitted to the Secretary of State no later than December 7, 2007.
Appendix A, Exhibit 4: Declaration Regarding Material Assistance/Non-Assistance to a Terrorist Organization
The three-page declaration in this exhibit is a scanned form. The instructions, blank identity fields, six questions, response choices, certification, and signature labels are transcribed below. The form fields and checkboxes here describe the source; they are not interactive.
Instructions: read before completing your DMA form
For instructional use only. Forms not conforming to the specifications listed below or not submitted to the appropriate agency or office will not be processed.
- To complete this form, you will need a copy of the Terrorist Exclusion List for reference. The Terrorist Exclusion List can be found on the Ohio Homeland Security Web site at the following address: http://www.homelandsecurity.ohio.gov/dma.asp
- Be sure you have the correct DMA form. If you are applying for a state issued license, permit, certification or registration, the “State Issued License” DMA form must be completed (HLS 0036). If you are applying for employment with a government entity, the “Public Employment” DMA form must be completed (HLS 0037). If you are obtaining a contract to conduct business with or receive funding from a government entity, the “Government Business and Funding Contracts” DMA form must be completed (HLS 0038). The Pre-certification form (HLS 0035) should only be completed if you are specifically instructed to do so by the agency or office requesting the form.
- Your DMA form is to be submitted to the issuing agency or entity. “Issuing agency or entity” means the government agency or office that has requested the form from you or the government agency or office to which you are applying for a license, employment or a business contract. For example, if you are seeking a business contract with the Ohio Department of Commerce’s Division of Financial Institutions, then the form needs to be submitted to the Department of Commerce’s Division of Financial Institutions. Do not send the form to the Ohio Department of Public Safety unless you are seeking a license from or employment or business contract with one of its eight divisions listed below.
Department of Public Safety divisions:
- Administration
- Ohio Bureau of Motor Vehicles
- Ohio Emergency Management Agency
- Ohio Emergency Medical Services
- Ohio Homeland Security
- Ohio Investigative Unit
- Ohio Criminal Justice Services
- Ohio State Highway Patrol
Do not send the form to Ohio Homeland Security unless otherwise directed. Forms sent to the wrong agency or entity will not be processed.
Government business and funding contracts declaration
Ohio Department of Public Safety, Division of Homeland Security. In accordance with section 2909.33 of the Ohio Revised Code.
Declaration regarding material assistance/no assistance to a terrorist organization. This form serves as a declaration of the provision of material assistance to a terrorist organization or organization that supports terrorism as identified by the U.S. Department of State Terrorist Exclusion List (see the Ohio Homeland Security Division Web site for reference copy of the Terrorist Exclusion List).
Any answer of “yes” to any question, or the failure to answer “no” to any question on this declaration shall serve as a disclosure that material assistance to an organization identified on the U.S. Department of State Terrorist Exclusion List has been provided. Failure to disclose the provision of material assistance to such an organization or knowingly making false statements regarding material assistance to such an organization is a felony of the fifth degree.
For the purposes of this declaration, “material support or resources” means currency, payment instruments, other financial securities, funds, transfer of funds, and financial services that are in excess of one hundred thousand dollars, as well as communications, lodging, training, safe houses, false documentation or identification, communications equipment, facilities, weapons, lethal substances, explosives, personnel, transportation, and other physical assets, except medicine or religious materials.
Complete this section only if you are an independent contractor
The following fields are blank in the source form:
- Last name
- Blank.
- First name
- Blank.
- MI (middle initial)
- Blank.
- Home address
- Blank.
- City
- Blank.
- State
- Blank.
- ZIP
- Blank.
- County
- Blank.
- Home phone
- Blank.
- Work phone
- Blank.
Complete this section only if you are a company, business or organization
The following fields are blank in the source form:
- Last name
- Blank.
- First name
- Blank.
- MI (middle initial)
- Blank.
- Business/organization name
- Blank.
- Phone
- Blank.
- Business address
- Blank.
- City
- Blank.
- State
- Blank.
- ZIP
- Blank.
- County
- Blank.
Declaration questions
In accordance with section 2909.32 (A)(2)(b) of the Ohio Revised Code. For each question, indicate either “yes” or “no” in the space provided. Responses must be truthful to the best of your knowledge. Both response boxes are empty for each question in the source form.
- Are you a member of an organization on the U.S. Department of State Terrorist Exclusion List? Responses: Yes (blank); No (blank).
- Have you used any position of prominence you have with any country to persuade others to support an organization on the U.S. Department of State Terrorist Exclusion List? Responses: Yes (blank); No (blank).
- Have you knowingly solicited funds or other things of value for an organization on the U.S. Department of State Terrorist Exclusion List? Responses: Yes (blank); No (blank).
- Have you solicited any individual for membership in an organization on the U.S. Department of State Terrorist Exclusion List? Responses: Yes (blank); No (blank).
- Have you committed an act that you know, or reasonably should have known, affords “material support or resources” to an organization on the U.S. Department of State Terrorist Exclusion List? Responses: Yes (blank); No (blank).
- Have you hired or compensated a person you knew to be a member of an organization on the U.S. Department of State Terrorist Exclusion List, or a person you knew to be engaged in planning, assisting, or carrying out an act of terrorism? Responses: Yes (blank); No (blank).
In the event of a denial of a government contract or government funding due to a positive indication that material assistance has been provided to a terrorist organization, or an organization that supports terrorism as identified by the U.S. Department of State Terrorist Exclusion List, a review of the denial may be requested. The request must be sent to the Ohio Department of Public Safety’s Division of Homeland Security. The request forms and instructions for filing can be found on the Ohio Homeland Security Division Web site.
Certification
I hereby certify that the answers I have made to all of the questions on this declaration are true to the best of my knowledge. I understand that if this declaration is not completed in its entirety, it will not be processed and I will be automatically disqualified. I understand that I am responsible for the correctness of this declaration. I understand that failure to disclose the provision of material assistance to an organization identified on the U.S. Department of State Terrorist Exclusion List, or knowingly making false statements regarding material assistance to such an organization is a felony of the fifth degree. I understand that any answer of “yes” to any question, or the failure to answer “no” to any question on this declaration shall serve as a disclosure that material assistance to an organization identified on the U.S. Department of State Terrorist Exclusion List has been provided by myself or my organization. If I am signing this on behalf of a company, business or organization, I hereby acknowledge that I have the authority to make this certification on behalf of the company, business or organization referenced on page 1 of this declaration.
- Applicant signature, marked X
- Blank signature line.
- Date
- Blank date line.
The scanned form is identified as HLS 0038 8/06 and has its own printed pagination, “Page 1 of 3” through “Page 3 of 3.”
Appendix B, Exhibit 1: Security Plan for Ohio Risk Assessment Study and Source Code Review
- Compliance with this security plan is mandatory for all participants in the project with access to the voting system source code and confidential information, including the Secretary of State (the “Secretary”), the Contractor, the Contractor’s team members, the Subcontractors and the Subcontractors’ team members (“project participants” or “team members” or “participants in the Project”). The Secretary and the project participants acknowledge that each will be responsible for complying with this security plan and have been informed of the Confidential Agreement that requires that source code and confidential information be kept confidential.
Chain of Custody
- The voting machine vendor will be responsible for securely transporting the voting system source code and confidential information to the State of Ohio Computer Center (SOCC). If the documents and source code are encrypted, the voting machine vendor will also be responsible for separately and securely transporting the encryption key to the SOCC. An authorized employee of the Secretary will sign for and accept the delivery of each source code and encryption key transported to the SOCC.
- The Secretary will securely store the source code and confidential information in a safe and secure location at the SOCC until the participants in the Project are ready to begin the work. Only authorized employees of the Secretary, and review team members as described below, will have access to the contents of the safe/secure container/secure area.
- An authorized employee of the Secretary will reproduce the voting system source code to enable risk assessment testing at no more than three additional remote secure locations. The Secretary is responsible for securely transporting the voting system source code to those remote secure locations. If the source code is encrypted, the Secretary will also be responsible for separately and securely transporting the encryption key to the three remote secure locations.
- A separate chain of custody log will be established and maintained for each copy of source code and confidential documents sent to the SOCC and remote locations. Any authorized person accessing the source code must sign the chain of custody log and identify which source code is being moved for examination and testing. A second Secretary of State representative or team member working on the project must verify each chain of custody log entry.
Secure Facilities
- Project participants agree that there will be a secure/locked room or rooms where the work is to be performed. Access to the room will be limited to the project participants. The room will be kept locked at all times. A log will be kept of everyone who receives a key or access code to the room.
- Access to source code and confidential materials will be allowed to someone only after they have signed or acknowledged the relevant Confidentiality Agreement, and the Security Plan.
- The room will contain dedicated computers that may be used for processing source code or reviewing vendor provided confidential information. Source code and confidential information will not be installed on other machines.
- For sites using desktop computers, each PC will have an external (e.g., a USB or Firewire) or removable hard disk. Team members will exercise reasonable caution to ensure that all source code and related information is installed and stored only on the external/removable hard drive, not on the PC’s internal hard drive. Sites using laptop devices will store the entire device in the safe/secure container when they are not in use.
- Except as otherwise provided in this Security Plan, no person may bring any removable storage device or media into the room with the source code.
- Confidential information, print-outs and other paper documents containing confidential or sensitive material will remain in the secure room and will not be removed from it. In the case where teams use two adjoining secure rooms for their work, print-outs and working notes may be hand-carried temporarily from one secure room immediately to another so long as they remain under that project participant’s secure personal control while they are transported.
Labeling
- The project participants’ room(s) will use strict “air-gap” security and military-style red-black separation.
- The room will contain a supply of brightly colored labels. Any machine or device or storage media that contains or is involved in processing source code will be clearly labeled red. Any network cable that is attached to a red device will be clearly labeled red on both ends. Any device that is connected to a red network cable will be clearly labeled red. All dedicated computers in the room will be labeled red. All such devices will be securely stored when not in use.
- The red network must be contained entirely within the physical security perimeter of the room. No machine or device in the room will be plugged into any network cable that extends outside the room at any time. No red computer will have Internet access at any time.
- External hard disks and removable storage media (e.g., USB dongles, CD-Rs, DVD-Rs) will be labeled red once the source code has been installed on them. CD-Rs may be marked to identify them as “Confidential” in some other way (e.g., using a red pen).
- Once a machine or storage device has been labeled red, it must remain labeled red. Nothing that is labeled red may be removed from the secure room. Confidential information, printouts, and other paper documents containing confidential or sensitive material will remain in the room at all times, except as stated in Point 11. These items must be shredded when no longer needed, or at the end of the project.
- Exception: For the purposes of enabling delivery of final reports to the Secretary, off-site backups of working notes, draft reports, and other data, the team leader may authorize the creation of encrypted project files. The data will be encrypted using a cryptographic-strength program, such as GPG/PGP, with a high-security key or pass-phrase held closely by the team leader. Such data will then be written in encrypted form onto a CD-R or a DVD-R, which will be labeled as “Confidential” and may then be removed from the premises and stored at a secure facility separately from the cryptographic key. Any such encrypted data that is removed from the premises must be stored at a secure facility separately from the cryptographic key. Backup discs will be destroyed upon completion of the review of that voting system. Final reports can be transferred to the Secretary, whose office is permitted to keep these documents in perpetuity.
- Blank CD-R and DVD-R disks and removable devices are to be serialized and a written log kept of their use. No use of removable media is allowed for any reason without logging its purpose.
Clean-Desk Policy
- Before leaving the room at the end of the day, team members at remote facilities will disconnect their external hard drives and secure the hard drives, along with any confidential information, working notes, removable storage media, etc., in the safe/secure container/secure area.
- The last project participant to leave the room will check that all external hard disks, any confidential documents, working notes, or removable storage media from the source code reviewers have been placed into the safe/secure container/secure area. The last project participant to leave must verify that the room and contents are in safe/secure container/secure area and the door to the room is locked.
Personal Laptops
- Team members may bring laptops into the facility, subject to the following restrictions:
- Vendor source code must never be installed on personal laptops.
- Team members may use removable storage media (e.g., CD-Rs, DVD-Rs, USB dongles) to transfer files from laptops to red PCs in a unidirectional fashion. Read-only media are preferred for this purpose. However, files shall not be transferred from red PCs to any other (non-red) medium, except as specified in Point 17. A log entry of all media must be kept so that destruction of that media can be assured at the end of the project.
Communication
- Team members may communicate via Internet with other project participants about confidential matter *ONLY* in the form of e-mail encrypted using GPG/PGP. Other forms of Internet communication must not be used except for messages containing no confidential content (e.g., to schedule a phone call). Source code must never be transmitted by any form of e-mail or Internet communication, whether encrypted or unencrypted. For the purpose of auditing, accounts and GPG/PGP keys created specifically for this project will be used for all such communications.
- Team members may use telephone to communicate with other project participants.
- Team members must avoid discussing confidential information in public spaces where others might potentially overhear.
Completion of the Project
- Upon completion of this project, the team leader must perform or witness the secure erasure of all storage media, devices, and PCs labeled red, before they are removed from the room (e.g., to ship them back to the Secretary of State). The secure erase tool should use a low-level overwrite at DOD level process of the entire partition.
- Destruction of the media must be witnessed and logged by those witnesses.
- After securely erasing red USB flash drives, these devices and all CD-Rs and DVD-Rs must be physically destroyed or damaged to prevent inadvertent reuse.
Appendix B, Exhibit 2: Confidentiality Agreement
This Confidentiality Agreement is between the Ohio Secretary of State (the “Secretary”), located at 180 E. Broad Street Columbus, Ohio 43215, and SysTest Labs Inc., (“Contractor”), a Colorado corporation, with offices at 216 16th Street, Suite 700, Denver, Colorado 80202, and The University of Pennsylvania (“Subcontractor”), located at the Office of Research Services, 3451 Walnut Street P-221, Philadelphia, PA 19104-6205.
Article I: Definitions
1.01 Confidential Information. As used in this Confidentiality Agreement, the term “Confidential Information” refers to firmware and software, including source code and object code, and documentation for the voting systems that have been provided to the Secretary by the Vendor.
Confidential Information shall include Proprietary Documentation. As used in this Agreement, the term “Proprietary Documentation” shall include any proprietary documents/materials associated with the voting systems provided to the Reviewers by the Secretary including, without limitation, technical data packages. Proprietary Documentation may include materials protected by federal copyright law and the Reviewers agree to honor Vendor’s copyrights in a manner that is consistent with federal copyright law.
All Confidential Information and Proprietary Documentation shall be appropriately labeled in writing at the time of the disclosure as “Confidential Information or Proprietary Documentation”; and all orally disclosed Confidential Information shall be reduced to writing within fifteen (15) days of the date of the disclosure.
The Secretary and Reviewers shall ensure that any copies made of Confidential Information shall retain their appropriate labels regarding their confidential nature.
Confidential Information does not include information that:
- was already in the possession of the Reviewers before disclosure by the Secretary, and was received by the Reviewers without obligation of confidence;
- is independently developed by the Reviewers;
- is or becomes publicly available without breach of this Confidentiality Agreement;
- is rightfully received by the Reviewers from a third party without an obligation of confidence;
- is disclosed by the Reviewers with the written consent of the Secretary; or
- is released in accordance with a valid order of a court or governmental agency, provided that the Reviewers (1) notify the Secretary of such order immediately upon receipt of the order and (2) cooperate with the Secretary in any effort she chooses to make to obtain a protective order from the issuing court or agency limiting disclosure and use of the information solely for the purposes intended to be served by the original order of production.
1.02 Reviewers. As used in this Agreement, the term “Reviewers” refers collectively and individually to Contractor and Subcontractor, including their employees, subcontractors and agents who are contracted to perform services for the Secretary’s Risk Assessment Study. No Reviewer currently employed by a Vendor or a business competitor of a Vendor shall have access to the Confidential Information.
1.03 Residuals. “Residuals” means intangible ideas, concepts, know-how, and/or techniques that are retained solely in human memory by the Secretary, the Secretary’s employees, or the Reviewers who access the Confidential Information in connection with the Risk Assessment Study and who have made no effort to either memorize information in the Confidential Information or to refresh their recollection by reviewing any Confidential Information in anticipation of or in conjunction with the use of Residuals.
1.04 Risk Assessment Study. As used in this Confidentiality Agreement, the term “Risk Assessment Study” refers to the Tasks and Deliverables identified in the Statement of Work identified in the Sponsored Research Subcontract Agreement entered into between the Contractor and Subcontractor as a subcontract to Ohio Secretary of State Contract Number 2008-013.
1.05 Vendor. As used in this Agreement, the term “Vendor” refers to Ohio’s voting system manufacturers who have provided Confidential Information to the Secretary for purposes of the Risk Assessment Study.
Article II: Introduction
2.01 The purpose of this Agreement is to enable full implementation of the Risk Assessment Study while protecting the Vendor’s protected proprietary rights from unauthorized disclosure and/or unauthorized use or misuse.
Article III: Term
3.01 The rights and responsibilities set forth in this Confidentiality Agreement shall survive termination of Personal Services Contract SOS Contract No. 2008-012 between the Secretary and the Contractor and termination of the Sponsored Research Subcontract dated October 1, 2007 between the Contractor and Contractor. Notwithstanding the foregoing, none of the parties hereto shall have any obligation of confidentiality under this agreement ten years after the earlier to occur of (1) the conclusion of the Period of Performance of the Sponsored Research Agreement or (2) termination of the Sponsored Research Subcontract Agreement in accordance with Article 10, unless otherwise agreed in writing.
Article IV: Licenses
4.01 The Reviewers acknowledge that any firmware, software, source code, object code and/or Proprietary Documentation provided to the Secretary from the Vendors includes a non-exclusive, non-transferable, royalty free license, for the Secretary and/or the Reviewers to possess and utilize the Proprietary Documentation, firmware, software, source code, or object code solely and exclusively to carry out the Risk Assessment Study and for no other activities.
4.02 The Reviewers acknowledge that the license shall terminate 90 days after completion of the Risk Assessment Study.
4.03 The Reviewers shall not transfer, assign, or sublicense the license granted by the Vendor, in whole or in part, without the express written consent of the Secretary and the Vendor, and any unauthorized assignment or transfer shall be null and void for all purposes. No implied licenses will be granted or recognized.
4.04 The Reviewers acknowledge that the license is limited solely to the Secretary’s and the Reviewers’ internal activities related to the Risk Assessment Study and does not extend to any other entity or activity.
Article V: Confidentiality
5.01 The Reviewers shall not disclose any Confidential Information to third parties. For purposes of this agreement, third parties do not include: (1) the Reviewers’ employees, Subcontractors, or agents who have a need to access the Confidential Information in connection with the Risk Assessment Study; and (2) the Secretary or the Secretary’s employees or agents who have a need to access the Confidential Information in connection with the Risk Assessment Study. For purposes of communications and transmittals of Confidential Information under this Agreement, the respective authorized representatives of the parties are:
- Subcontractor
- Dr. Matthew Blaze. Phone: 215-573-2696. Email: [email protected].
- Contractor
- Geoffrey Pollich. Phone: 303-249-0445. Email: [email protected].
- Secretary
- Terry Dick. Phone: 614-728-4380. Email: [email protected].
5.02 The Reviewers shall treat the Confidential Information as confidential and shall use the Confidential Information solely in connection with the Risk Assessment Study.
5.03 The Contractor shall not incorporate any portion of any Confidential Information into any work or product, other than what is provided for in the Statement of Work in Personal Services Contract No. 2008-012, and will have no proprietary interest in any of the Confidential Information. Subcontractor shall not incorporate any portion of any Confidential Information into any work or product, other than what is provided for in the Statement of Work in the Sponsored Research Subcontract Agreement entered into between the Contractor and Subcontractor as a subcontract to Ohio Secretary of State Contract Number 2008-013, and will have no proprietary interest in any of the Confidential Information.
5.04 The Reviewers shall return all originals of any Confidential Information and destroy on termination or expiration of this Agreement any copies it has made. The Reviewers shall notify the Secretary when destruction has been completed.
5.05 Notwithstanding the foregoing, Residuals, as defined in Section 1.03 of this Agreement, shall not be subject to restrictions on disclosure or use. The parties acknowledge that the Reviewers may have previously researched and published articles or other written materials concerning voting technology topics, possibly including Ohio’s voting systems; so long as they comply with the other terms of this Confidentiality Agreement, they are not constrained from conducting and publishing additional research concerning voting systems following the completion of the Risk Assessment Study.
5.06 The Contractor and Subcontractor shall not disclose the Confidential Information to any of their subcontractors, employees or agents unless and until those subcontractors, employees or agents have read, acknowledged, and agreed to honor this Agreement by executing Appendix B, Exhibit 3 of the Sponsored Research Subcontract Agreement entered into between the Contractor and Subcontractor as a subcontract to Ohio Secretary of State Contract Number 2008-013.
5.07 Except as set forth below, the Reviewers will be liable for the disclosure of Confidential Information whether it is intentional or negligent unless otherwise provided in this paragraph. The Reviewers shall not be liable for any negligent disclosure of Confidential Information that results despite the Reviewers’ exercise of at least the same degree of care as it normally takes to safeguard its own Confidential Information.
5.08 The Secretary and the Reviewers acknowledge that the Confidential Information may be subject to disclosure under Ohio Revised Code Section 149.43 (the Ohio Public Records Act). To the extent that the Confidential Information is exempt from such disclosure, it shall not be released pursuant to a public records act request made in accordance with Ohio Revised Code Section 149.43. The Reviewers shall promptly notify the Secretary of any request for release of Confidential Information under Ohio Revised Code Section 149.43 and agree not to disclose the Confidential Information until the Secretary has determined within a reasonable time whether a protective order should be sought to protect the Confidential Information from disclosure.
5.09 With the exception of reports provided to the Ohio Secretary of State pursuant to the Sponsored Research Subcontract Agreement, Reviewers agree not to publish or otherwise disclose the Confidential Information. The Ohio Secretary of State acknowledges Reviewers’ right to publish results of the Risk Assessment Study consistent with the terms of this Confidentiality Agreement. Contractor shall have no right to review reports or other written material prepared for publication by Subcontractor.
5.10 The Reviewers understand that the Secretary will release the public version of the research reports promptly after they are delivered, and in no event after more than 45 days after they are delivered. Until a team’s research findings are made public by the Secretary, or 45 days after delivery of a report to the Secretary, whichever is sooner, the Reviewers will not publicly comment on the progress, procedures, processes or findings of that team and will defer any press or other inquiries about the study to the Secretary’s office. However, after conferring with the Secretary, the Reviewers reserve the right to respond to any factual misrepresentations or errors about the progress, procedures, processes or findings, or critical statements about the Reviewers within the constraints of this Confidentiality Agreement.
5.11 Reviewers and each of Reviewers’ agents, subcontractors, employees, and personnel who perform services for the Risk Assessment Study shall not use the Confidential Information in the creation of election equipment or in the performance of maintenance, ballot layout and design, or services related to the sale and maintenance of election equipment for at least 10 years from the date of the Agreement.
IN WITNESS WHEREOF, the parties have executed this Confidentiality Agreement as evidenced by their signatures below.
The source contains unsigned signature lines for the three parties:
- Secretary
- By: blank signature line, with “Jennifer Brunner” printed beneath. Address: 180 East Broad St, Columbus OH 43215. Title: Ohio Secretary of State. Date: blank.
- SysTest Labs, Incorporated
- By: blank signature line. Address: 216 16th Street, Suite 700, Denver, Colorado 80202. Title: blank. Date: blank.
- The University of Pennsylvania
- By: blank signature line. Address: two blank lines. Title: blank. Date: blank.
Appendix B, Exhibit 3: Acknowledgement of Having Read Security Plan and Confidentiality Agreement
I acknowledge that I have read both the SECURITY PLAN FOR RISK ASSESSMENT STUDY AND SOURCE CODE REVIEW, labeled Appendix B, Exhibit 1, and the CONFIDENTIALITY AGREEMENT, labeled Appendix B, Exhibit 2, copies of which are attached to this document.
The PDF provides 16 “READ AND ACKNOWLEDGED” blocks, arranged in two columns across pages 24 and 25. Every block has the same three blank labels: By, Date, and Print Name and Role. None is completed.
- Read and acknowledged, block 1: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 2: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 3: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 4: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 5: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 6: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 7: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 8: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 9: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 10: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 11: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 12: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 13: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 14: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 15: By — blank; Date — blank; Print Name and Role — blank.
- Read and acknowledged, block 16: By — blank; Date — blank; Print Name and Role — blank.