https://techsolidarity.org/resources/congressional_howto.htm...
In comparison:
* This is way too long and full of technical jargon. Even relatively major campaigns still aren't staffed with technical experts. Very few do their own application development. The person managing IT probably has 30 other jobs.
* This "checklist" has no coherent notion of the actual threat model campaigns face. It's just a laundry list of security advice of the sort a bank would provide to a downstream business partner.
* It's extremely casual about the two biggest threats campaigns face --- phishing and attachments. Campaigns need clear, actionable advice for dealing with these, and "be careful about links" absolutely doesn't cut it --- your mental model of phishing should be that it always works, and the attack needs to be broken directly (security key authentication has the virtue of actually doing this; "two factor authentication" does not).
* It contains silly advice, like "modern anti-malware" and "install a WAF".
This list would be unimpressive and ineffective even in trying to secure a small business that actually had an IT team. I don't think it will be helpful at all to campaigns.