Each county auditor shall implement no later than July 1, 2027, cybersecurity measures including but not limited to:
(1) Implementation and adoption of the ".gov" top-level domain available through the United States department of homeland security through the cybersecurity and infrastructure security agency for all election and voting systems and infrastructure. This adoption is required for election and voting systems and websites and may include all county cyber assets and email domains.
(2) Partitioning the entire auditor's office, including all of its information technology systems and assets, or specifically partitioning election and voting information technology infrastructure from other county assets. The secretary of state shall consult with county auditors on which systems and assets need to be partitioned or technologically isolated and protected. Eliminating threat actors from moving laterally within a network to target election-related capabilities is paramount. The secretary of state may extend the deadline for a county auditor to comply with this subsection if more time is necessary for implementation.
(3) Isolation of all ballot counting equipment and voting system components as defined in RCW 29A.12.005 from any other network including:
(a) Internal networks within a county election office;
(b) Printer sharing networks external to the ballot counting system;
(c) The internet, world wide web, or other similar networks;
(d) Wifi and radio connectivity;
(e) Wired connectivity; and
(f) Any telephonic or other connectivity.
(4) No configuration of voting systems to:
(a) Establish a connection to an external network; or
(b) Connect to any device external to the voting system.
(5) Purchase of voting systems that include documentation listing security configurations and network security best practices and operating those systems used for conducting primaries and elections in a manner consistent with that documentation.
(6) Restricting all data transfers from any voting system to using single-use, previously erased devices that contain no information prior to connection with the system. This includes pen drives, flash memory drives, memory sticks, and any other removal media used to transfer data. Devices used in data transfer must either be provided by the secretary of state to the county auditor for single use, or the media must be overwritten by the county auditor by following guidelines for media sanitization defined in rules promulgated by the secretary of state.