Home > 2.8 Security > 04. ESTONIA - Riigikogu Election Act
 
 
 
Download file    
 
 
Article 48
 

Ensuring security of elections


[RT I, 24.05.2024, 1 – entry into force 03.06.2024]


(1) The electronic voting system must comply with the requirements of the Cybersecurity Act.


(2) Before electronic voting begins, the following is carried out with regard to the electronic voting system:


1) risk assessment;


2) audit of the applied security measures;


3) technical penetration testing;


4) a risk treatment plan for mitigating significant risks, prepared on the basis of the results of the risk assessment, the non-compliances highlighted in the audit report and the findings of the penetration testing.


(3) The electronic voting system must use an appropriate and up-to-date cryptographic algorithm. The exact specification of the cryptographic algorithm is determined by the State Electoral Office each time before the elections.


(4) An information systems auditor must be present at the generation, use and destruction of secret keys used for electronic voting.


[RT I, 24.05.2024, 1 – entry into force 03.06.2024]